CVE-2002-2127
2.1 · LOWOverview
CVE-2002-2127 is a low-severity vulnerability affecting pedestal_software integrity_protection_driver. It was published on December 31, 2002 and has a CVSS 2.0 base score of 2.1 (LOW).
This vulnerability has a CVSS 2.0 base score of 2.1, rated LOW. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
Technical Description
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.
Remediation
Check the references section for vendor advisories and patches from pedestal_software. Update integrity_protection_driver to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|
References
Frequently Asked Questions
What is CVE-2002-2127?
CVE-2002-2127 is a low-severity vulnerability affecting pedestal_software integrity_protection_driver. It was published on December 31, 2002 and has a CVSS 2.0 base score of 2.1 (LOW).
How severe is CVE-2002-2127?
This vulnerability has a CVSS 2.0 base score of 2.1, rated LOW. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2002-2127?
Check the references section for vendor advisories and patches from pedestal_software. Update integrity_protection_driver to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2002-2127?
CyberStrike's AI-powered security agents can automatically detect CVE-2002-2127 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related LOW CVEs from 2002
View all →Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted it
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to
Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and ear
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with worl
PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local us
The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems al
The web interface for Webmin 0.92 does not properly quote or filter script code in files that are di
Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code
The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attach
Next Generation POSIX Threading (NGPT) 1.9.0 uses a filesystem-based shared memory entry, which allo
Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to v