Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrcf-p229-q8r2

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction.

IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction.

EPSS

Процентиль: 91%
0.06153
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction.

CVSS3: 5.5
fstec
больше 7 лет назад

Уязвимость утилиты для оптимизации IOBit Advanced SystemCare, связанная с ошибками управления привилегиями, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 91%
0.06153
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119