Описание
The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory addresses because the IOCTL dispatcher lacks pointer validation. Exploiting this vulnerability results in privileged code execution.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.5 (включая)
cpe:2.3:a:winmagic:securedoc:*:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00115
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-119
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory addresses because the IOCTL dispatcher lacks pointer validation. Exploiting this vulnerability results in privileged code execution.
EPSS
Процентиль: 31%
0.00115
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-119