Vulnerability Description
The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eset | Endpoint Encryption | < 5.1.2.26 |
| Eset | Full Disk Encryption | < 1.3.2.32 |
Related Weaknesses (CWE)
References
- https://support.eset.com/en/ca8298-vulnerability-fixed-in-eset-endpoint-encryptiVendor Advisory
- https://support.eset.com/en/ca8298-vulnerability-fixed-in-eset-endpoint-encryptiVendor Advisory
FAQ
What is CVE-2022-2402?
CVE-2022-2402 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.
How severe is CVE-2022-2402?
CVE-2022-2402 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2402?
Check the references section above for vendor advisories and patch information. Affected products include: Eset Endpoint Encryption, Eset Full Disk Encryption.