First published: Thu Feb 01 2018(Updated: )
The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code with SYSTEM privileges via a crafted 0x83170180 call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Total Protection | <=24.0.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3752 is classified as a high-severity vulnerability due to the potential for local users to execute arbitrary code with SYSTEM privileges.
To mitigate CVE-2014-3752, update G Data TotalProtection to version 24.0.2.2 or later.
CVE-2014-3752 is a local privilege escalation vulnerability in the MiniIcpt.sys driver.
CVE-2014-3752 affects local users with administrator rights on systems running G Data TotalProtection 2014 version 24.0.2.1 or earlier.
Exploiting CVE-2014-3752 allows an attacker to execute arbitrary code with high-level SYSTEM privileges, potentially compromising the entire system.