[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
NGS00193 Patch Notification: Trend Micro DataArmor and DriveArmor - Restricted Environment breakout, Privilege Escalation and Full Disk Decryption
- To: "bugtraq@xxxxxxxxxxxxxxxxx" <bugtraq@xxxxxxxxxxxxxxxxx>
- Subject: NGS00193 Patch Notification: Trend Micro DataArmor and DriveArmor - Restricted Environment breakout, Privilege Escalation and Full Disk Decryption
- From: "Research@NGSSecure" <research@xxxxxxxxxxxxx>
- Date: Tue, 24 Jan 2012 14:36:32 +0000
Critical Vulnerability in DataArmor and DriveArmor
24 January 2012
Stuart Passe of NGS Secure has discovered a Critical vulnerability in DataArmor
and DriveArmor.
Impact: Restricted Environment breakout, Privilege Escalation and Full Disk
Decryption
Versions affected:
DataArmor 3.0.10 or greater
DriveArmor 3.0.0 or greater
An updated version of the software has been released to address these
vulnerabilities:
http://esupport.trendmicro.com/solution/en-us/1060043.aspx
NGS Secure is going to withhold details of these flaws for three months. This
three month window will allow users the time needed to apply the patch before
the details are released to the general public. This reflects the NGS Secure
approach to responsible disclosure.
NGS Secure Research
http://www.ngssecure.com