Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpw6-98jf-9gjm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege escalation. An attacker can send an IRP request to trigger this vulnerability.

An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege escalation. An attacker can send an IRP request to trigger this vulnerability.

EPSS

Процентиль: 39%
0.00172
Низкий

7.8 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.3
nvd
около 7 лет назад

An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege escalation. An attacker can send an IRP request to trigger this vulnerability.

CVSS3: 9.3
fstec
около 7 лет назад

Уязвимость обработчика 0x8200E804 IOCTL программного обеспечения аппаратных ключей защиты WibuKey, позволяющая нарушителю осуществить повреждение памяти ядра

EPSS

Процентиль: 39%
0.00172
Низкий

7.8 High

CVSS3

Дефекты

CWE-119