Deslock provides endpoint encryption and data protection software, with its vulnerability footprint concentrated in the single Deslock product. The vendor's disclosures recur around memory-safety and input-validation weaknesses such as buffer-boundary violations and improper input handling, which are characteristic of encryption and file-access control layers, and frequently acquire public exploit code. Current exploitation activity, severity distribution, and exposure scope are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deslock over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4832HIGH The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryptCore device. | Apr 29, 2010 | 7.2 | 29 | NO | YES |
CVE-2008-4363HIGH DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \ | Sep 30, 2008 | 7.2 | 27 | NO | YES |
CVE-2008-1139HIGH DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain privileges via a certain DLMFENC_IOCTL request to \\.\DLKPFS | Mar 4, 2008 | 7.2 | 27 | NO | YES |
CVE-2008-1140HIGH DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL request to \\.\DLKFDisk_Control that overwrites a data struct | Mar 4, 2008 | 7.2 | 27 | NO | YES |
CVE-2017-12840HIGH A kernel driver, namely DLMFENC.sys, bundled with the DESLock+ client application 4.8.16 and earlier contains a locally exploitable heap based buffer overflow in the handling of an | Aug 28, 2017 | 7.8 | 25 | NO | NO |
CVE-2008-1141MEDIUM Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kernel memory consumption) via a series of DLMFENC_IOCTL requests | Mar 4, 2008 | 4.9 | 24 | NO | YES |
CVE-2008-4362MEDIUM The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \Device\DLPTokenWal | Sep 30, 2008 | 4.9 | 22 | NO | YES |
CVE-2008-1138MEDIUM DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a certain ZERO_MEM DLMFENC_IOCTL request to \\.\DLKPFSD_Device | Mar 4, 2008 | 4.9 | 22 | NO | YES |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deslock.
Media articles that mention a CVE ID that affects a product developed by Deslock — matched by CVE ID, not by vendor name.