CVE-2003-1233
Last modified
CVE-2003-1233 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pedestalsoftware | Integrity Protection Driver | <= 1.3 |
References
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.htmlBroken Link, Patch
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.htmlBroken Link, Exploit, Patch
- http://secunia.com/advisories/7816Broken Link, Patch, Vendor Advisory
- http://www.phrack.org/show.php?p=59&a=16Broken Link
- http://www.securityfocus.com/bid/6511Broken Link, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10979Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.htmlBroken Link, Patch
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.htmlBroken Link, Exploit, Patch
- http://secunia.com/advisories/7816Broken Link, Patch, Vendor Advisory
- http://www.phrack.org/show.php?p=59&a=16Broken Link
- http://www.securityfocus.com/bid/6511Broken Link, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10979Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1233?
How severe is CVE-2003-1233?
How do I fix CVE-2003-1233?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-1227PHP remote file include vulnerability in index.php for Galle…
- CVE-2003-1228Buffer overflow in the prepare_reply function in request.c f…
- CVE-2003-1229X509TrustManager in (1) Java Secure Socket Extension (JSSE) …
- CVE-2003-1230The implementation of SYN cookies (syncookies) in FreeBSD 4.…
- CVE-2003-1231Cross-site scripting (XSS) vulnerability in index.php in ECW…
- CVE-2003-1232Emacs 21.2.1 does not prompt or warn the user before executi…
- CVE-2003-1234Integer overflow in the f_count counter in FreeBSD before 4.…
- CVE-2003-1235BRW WebWeaver 1.03 allows remote attackers to obtain sensiti…
- CVE-2003-1236Multiple format string vulnerabilities in the logger functio…
- CVE-2003-1237Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1…
- CVE-2003-1238Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 b…
- CVE-2003-1239Directory traversal vulnerability in sendphoto.php in WihPho…
Are you affected by CVE-2003-1233?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
