Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhv6-3xv8-6vhf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, via a function call such as MmMapIoSpace.

The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, via a function call such as MmMapIoSpace.

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
около 6 лет назад

The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, via a function call such as MmMapIoSpace.

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-269