PT-2014-7797 · K7 Computing · K7Fwfilt.Sys

Publicado

2014-12-12

·

Atualizado

2014-12-15

·

CVE-2014-7136

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions K7FWFilt.sys versions prior to 14.0.1.16
Description A heap-based buffer overflow issue exists in the K7FWFilt.sys kernel mode driver, which can be exploited by local users to execute arbitrary code with kernel privileges. This is achieved by passing a crafted parameter in a DeviceIoControl API call.
Recommendations For versions prior to 14.0.1.16, update to version 14.0.1.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the DeviceIoControl API call to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7136

Produtos afetados

K7Fwfilt.Sys