First published: Tue Aug 26 2014(Updated: )
Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Panda Security Panda Antivirus Pro 2014 | =13.01.01 | |
Panda Global Protection | =7.01.01 | |
Panda Security | =19.01.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5307 is classified as a high severity vulnerability due to its potential for privilege escalation.
To address CVE-2014-5307, ensure that you update the affected Panda Security products to the latest version that includes the necessary patches.
CVE-2014-5307 affects Panda Antivirus Pro 2014, Panda Global Protection 2014, and Panda Internet Security 2014.
Exploiting CVE-2014-5307 allows local users to gain higher privileges on the system, potentially leading to unauthorized access and control.
CVE-2014-5307 is a heap-based buffer overflow vulnerability that occurs in the PavTPK.sys kernel mode driver.