This site uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Find out more.X

Symantec quells fears of PGP vulnerability

Share this article:

Symantec has quenched fears about a vulnerability in its PGP technology.

According to a Pastebin statement, the pgpwded.sys kernel driver distributed with Symantec PGP Desktop contains an arbitrary memory overwrite vulnerability in the handling of IOCTL 0x80022058.

While the statement admitted that an attacker would need local access to a vulnerable computer to exploit this vulnerability, successful exploitation of this issue would allow an attacker to execute arbitrary code.

The statement also said that this vulnerability (METHO_BUFFERED with output_size == 0) exploit works only on Windows XP/2003.

A Symantec blog acknowledged the discovery and reality of the vulnerability. Kelvin Kwan, product marketing manager at Symantec, said: “There is a potential issue, but it cannot easily be exploited.”

Kwan said that the exploit would be very difficult to trigger as it relies on the system entering an error condition first and once in this error condition, the exploit could allow an attacker with lower privileges to run some arbitrary code with higher privileges.

This vulnerability is limited to systems running Windows XP and Windows 2003 and is not present in later versions of Windows.  

Kwan said: “The plan is to have a fix in an upcoming maintenance pack. The expected availability of the maintenance pack is early February.”

Share this article:

SC webcasts on demand

This is how to secure data in the cloud


Exclusive video webcast & Q&A sponsored by Vormetric


As enterprises look to take advantage of the cloud, they need to understand the importance of safeguarding their confidential and sensitive data in cloud environments. With the appropriate security safeguards, such as fine-grained access policies, a move to the cloud is as, or more, secure than an on-premise data storage.


View the webcast here to find out more

More in News

Chinese hackers steal confidential documents on Israeli missile defence system

Chinese hackers steal confidential documents on Israeli missile ...

Chinese hackers comprised the computer systems of three Israeli defence contractors between 10 October 2011 and 13 August 2012 in order to steal hundreds on confidential documents on Israel's Iron ...

Security researcher finds exploitable flaws in 14 antivirus engines

Security researcher finds exploitable flaws in 14 antivirus ...

Joxean Koret, a security researcher at Singapore-based consultancy COSEINC, has found exploitable local and remote flaws in 14 of the 17 major antivirus (AV) engines used by most major AV ...

Russian government promises £60k bounty to Tor hackers

Russian government promises £60k bounty to Tor hackers

The Russian Ministry of Internal Affairs (MVD) is offering a 3.9 million ruble (approximately £64,600) reward to anyone who can find a way of identifying and tracking users of the ...