Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85p3-9hqw-5w58

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

EPSS

Процентиль: 34%
0.00139
Низкий

7.1 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.1
nvd
больше 7 лет назад

The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

EPSS

Процентиль: 34%
0.00139
Низкий

7.1 High

CVSS3

Дефекты

CWE-732