First published: Tue Apr 24 2018(Updated: )
Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additional insufficient checks allow any application to turn off some of the protection mechanisms provided by the Invincea product.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Invincea | =5.1.1-22303 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8732 is classified as a high severity vulnerability due to the potential for exploitation that allows malicious applications to disable protection mechanisms.
To fix CVE-2016-8732, users must update to a later version of Invincea Dell Protected Workspace that addresses these security flaws.
Exploitation of CVE-2016-8732 can lead to the bypassing of important security protections provided by the Invincea software, potentially exposing the system to further attacks.
CVE-2016-8732 affects Invincea Dell Protected Workspace version 5.1.1-22303.
The vendor for CVE-2016-8732 is Sophos, which developed the Invincea Dell Protected Workspace software.