Pedestalsoftware develops system integrity and file-protection drivers, with observed vulnerabilities centered on improper link-resolution logic that can enable unauthorized file access or modification. This represents a narrowly scoped vendor profile focused on a specific defensive mechanism and its attendant path-handling weaknesses; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pedestalsoftware over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1233CRITICAL Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using | Dec 31, 2003 | 9.8 | 30 | NO | NO |
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument. | Aug 17, 2004 | 2.1 | 14 | NO | NO |
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\s | Dec 31, 2003 | 2.1 | 11 | NO | NO |
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an | Dec 31, 2002 | 2.1 | 11 | NO | NO |
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by ac | Dec 31, 2002 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pedestalsoftware.
Media articles that mention a CVE ID that affects a product developed by Pedestalsoftware — matched by CVE ID, not by vendor name.