CVE-2018-6322: High severity Pandasecurity Panda Global Protection vulnerability
Published Mar 12, 2018
·Updated
Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\pipe\PSANMSrvcPpal -- an "insecurely created named pipe." Ensures full access to Everyone users group.
Affected Software
1 affected component
Pandasecurity Panda Global Protection=17.0.1
Event History
Mar 12, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6322?
CVE-2018-6322 has a high severity as it allows local users to gain elevated privileges or cause a denial of service.
2
How do I fix CVE-2018-6322?
To fix CVE-2018-6322, ensure that the named pipe is created securely, limiting access to authorized users only.
3
What is affected by CVE-2018-6322?
CVE-2018-6322 specifically affects Panda Global Protection version 17.0.1.
4
Who can exploit CVE-2018-6322?
Local users on the system can exploit CVE-2018-6322 due to the insecurely created named pipe.
5
What type of vulnerability is CVE-2018-6322?
CVE-2018-6322 is a local privilege escalation vulnerability due to improper access control.