PT-2018-15314 · Microsoft+1 · Ssdt.Sys+1
Publicado
2018-12-23
·
Atualizado
2018-12-31
·
CVE-2018-20331
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Antiy AVL ATool version 1.0.0.22
Description
The issue is caused by a failure to properly validate the length of user-supplied data in the processing of IOCTL 0x80002004 by the ssdt.sys kernel driver. This can lead to a Kernel Pool Buffer Overflow, allowing an attacker to execute arbitrary code in the context of the kernel, potentially resulting in privilege escalation. A failed exploit could lead to denial of service. The attacker must first obtain the ability to execute low-privileged code on the target system.
Recommendations
For Antiy AVL ATool version 1.0.0.22, as a temporary workaround, consider restricting access to the ssdt.sys kernel driver to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Antiy Avl Atool
Ssdt.Sys