DataArmor FDE Breakout & Privilege Escalation
ID: cba5559c-2f45-51ac-a9e0-881ea4e36f6b
STIX ID: report--cba5559c-2f45-51ac-a9e0-881ea4e36f6b
Feed Name: NCC Research
DataArmor Full Disk Encryption (versions prior to v3.0.12.861) contains a critical local vulnerability that allows an attacker with physical access to use the Linux Magic SysRq key to break out of the product's restricted X11 environment into a BusyBox root shell, modify authentication and policy files to add/escalate users, recover or fully decrypt the encrypted partition, and exfiltrate sensitive data; vendor fixes and mitigations (disable SysRq, recompile kernel, strip BusyBox utilities) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
