CVE-2008-1138
DESlock+ < 3.2.6 - Denial of Service via DLMFENC_IOCTL Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1138. PoCs published by mu-b.
AI-analyzed exploit summary This exploit targets a local kernel ring0 link list zero vulnerability in DESlock+ <= 3.2.6 by sending a crafted IOCTL request to the DLKPFSD_Device driver, potentially causing a system crash or privilege escalation.
Description
DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a certain ZERO_MEM DLMFENC_IOCTL request to \\.\DLKPFSD_Device, aka the "ring0 link list zero" vulnerability.
Exploits (1)
This exploit targets a local kernel ring0 link list zero vulnerability in DESlock+ <= 3.2.6 by sending a crafted IOCTL request to the DLKPFSD_Device driver, potentially causing a system crash or privilege escalation.