« Volver al listado

CVE-2009-0681

Estado: ModificadaAlta (7.2)—

PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0681",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-04-15T10:30:00.280",
  "references": [
    {
      "url": "http://en.securitylab.ru/lab/PT-2009-01",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/502633/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1022034",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://pgp.custhelp.com/cgi-bin/pgp.cfg/php/enduser/std_adp.php?p_faqid=1014&p_topview=1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://en.securitylab.ru/lab/PT-2009-01",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/502633/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1022034",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://pgp.custhelp.com/cgi-bin/pgp.cfg/php/enduser/std_adp.php?p_faqid=1014&p_topview=1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys."
    },
    {
      "lang": "es",
      "value": "PGP Desktop anterior a v9.10 permite a usuarios locales (1) provocar una denegación de servicio (caída) a través de peticiones IOCTL manipuladas en pgpdisk.sys, y (2) provocar una denegación de servicio (caída) y ejecutar código de su elección a través de una petición IOCTL con IRP manipulado en pgpwded.sys."
    }
  ],
  "lastModified": "2026-06-16T23:05:33.613",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pgp:desktop:*:-:home:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A96A401-F0D4-4B5B-A54D-81AF805BEA72",
              "versionEndIncluding": "9.9.0"
            },
            {
              "criteria": "cpe:2.3:a:pgp:desktop:*:-:pro:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D13E822C-2401-4BA2-9F58-BA5A65BB5B88",
              "versionEndIncluding": "9.9.0"
            },
            {
              "criteria": "cpe:2.3:a:pgp:desktop:8.0:*:home:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0745A00E-1A44-475D-A39B-6597CDB27AEC"
            },
            {
              "criteria": "cpe:2.3:a:pgp:desktop:8.0:*:pro:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEE891C4-7A40-4FF8-99A6-0CB57653B364"
            },
            {
              "criteria": "cpe:2.3:a:pgp:desktop:9.0:*:home:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1A4562F-4959-44F9-AFEC-21D640E7B640"
            },
            {
              "criteria": "cpe:2.3:a:pgp:desktop:9.0:*:professional:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B5BCE69-AA38-4321-8B95-A3CFDFCBC9E8"
            },
            {
              "criteria": "cpe:2.3:a:pgp:desktop:9.0.6:-:home:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1739BE5D-E639-4835-A080-E7D4B66EEEFB"
            },
            {
              "criteria": "cpe:2.3:a:pgp:desktop:9.0.6:-:pro:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAD65FDF-B51D-4898-8A09-0031BBACE335"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}