Winmagic provides disk encryption and data protection solutions centered on SecureDoc and its disk encryption product line, which target enterprise endpoint security. The vendor's observed weakness classes center on memory-safety issues such as buffer-boundary violations alongside certificate and search-path handling flaws, patterns typical of native encryption and device-management software. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winmagic over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20341HIGH WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an attacker to execute arbitrary code on a target system. If th | Apr 8, 2019 | 7.8 | 24 | NO | NO |
CVE-2020-11520HIGH The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory addresses because the IOCTL dispatcher lacks pointer validatio | Jun 22, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-11519HIGH The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sectors via a \\.\SecureDocDevice handle. Exploiting this vulner | Jun 22, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winmagic.
Media articles that mention a CVE ID that affects a product developed by Winmagic — matched by CVE ID, not by vendor name.