PT-2026-3059 · Unknown · Ludashi Driver

CVE-2025-67246

·

Publicado

2026-01-15

·

Atualizado

2026-01-17

CVSS v3.1

7.3

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ludashi driver versions prior to 5.1025
Description A local information disclosure issue exists in the Ludashi driver due to insufficient access control within the IOCTL handler. The driver provides a device interface accessible to standard users and processes structures controlled by attackers, which contain the lower 4GB of physical addresses. The handler utilizes MmMapIoSpace to map arbitrary physical memory and copies data to user mode without validating caller privileges or the target address range. This allows unprivileged users to read arbitrary physical memory, potentially exposing sensitive information such as kernel data structures, kernel pointers, and security tokens. This can be leveraged to bypass Kernel Address Space Layout Randomization (KASLR) and escalate privileges locally.
Recommendations Update the Ludashi driver to version 5.1025 or later.

Exploit

Correção

Improper Privilege Management

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67246

Produtos afetados

Ludashi Driver