First published: Thu Nov 20 2014(Updated: )
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Faronics Deep Freeze | <=8.10 | |
Faronics Deep Freeze | <=8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2382 is classified as a high severity vulnerability due to its potential for causing denial of service and executing arbitrary code.
To fix CVE-2014-2382, upgrade to a version of Faronics Deep Freeze that is later than 8.10.
CVE-2014-2382 affects local administrators using Faronics Deep Freeze Standard and Enterprise versions 8.10 and earlier.
CVE-2014-2382 can be exploited through crafted IOCTL requests that lead to denial of service or arbitrary code execution.
CVE-2014-2382 affects the DfDiskLo.sys driver within Faronics Deep Freeze.