Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-8372

Опубликовано: 18 фев. 2019
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lg:lha.sys:*:*:*:*:*:*:*:*
Версия до 1.1.1811.2101 (исключая)

EPSS

Процентиль: 40%
0.00184
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7
github
больше 3 лет назад

The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.

EPSS

Процентиль: 40%
0.00184
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59