First published: Wed Jul 27 2022(Updated: )
The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.
Credit: security@eset.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eset Endpoint Encryption | <5.1.2.26 | |
Eset Full Disk Encryption | <1.3.2.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2402 has a high severity as it leads to a kernel stack overflow and system crash.
CVE-2022-2402 affects users of Eset Endpoint Encryption versions prior to 5.1.2.26 and Eset Full Disk Encryption versions prior to 1.3.2.32.
To fix CVE-2022-2402, upgrade to Eset Endpoint Encryption version 5.1.2.26 or later and Eset Full Disk Encryption version 1.3.2.32 or later.
The implications of CVE-2022-2402 include potential system crashes and data loss due to the vulnerability in the dlpfde.sys driver.
CVE-2022-2402 requires a user to be logged into the system, thus it cannot be exploited remotely.