Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized processes to perform those actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications. Unauthorized processes load the driver and send a crafted IOCTL request (0xB822200C) to terminate processes protected by a third-party implementation. This action exploits insufficient caller validation in the driver's IOCTL handler, allowing unauthorized processes to perform termination operations in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Safetica Application 安全漏洞
Vulnerability Description
Safetica Application是美国Safetica公司的一款企业数据防泄漏与终端行为管控软件。 Safetica Application 11.11.4.0版本存在安全漏洞,该漏洞源于驱动程序IOCTL处理程序调用方验证不足,可能导致管理员权限用户发送特制IOCTL请求终止受保护进程,引发拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A