EPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\EPP device are not properly protected, leading to unintended impersonation or object creation. This vulnerability has been fixed in version 2018.12 and later.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-08T22:00:00

Updated: 2019-04-01T14:35:02

Reserved: 2019-02-08T00:00:00


Link: CVE-2019-7651

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-02-08T22:29:00.257

Modified: 2020-08-24T17:37:01.140


Link: CVE-2019-7651

JSON object: View

cve-icon Redhat Information

No data.