Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Doublelabyrinth

#32536of 53,622
7.8Total CVSS
Vulnerabilities · 1
PT-2019-19826
7.8
2019-03-12
Shanda · Shanda Maplestory Online · CVE-2019-9729
**Name of the Vulnerable Software and Affected Versions** Shanda MapleStory Online version V160 **Description** The issue arises from the SdoKeyCrypt.sys driver, which fails to validate the IOCtl 0x8000c01c input value. This oversight leads to an integer signedness error and a heap-based buffer underflow, ultimately allowing privilege escalation to NT AUTHORITYSYSTEM. **Recommendations** For Shanda MapleStory Online version V160, consider disabling the SdoKeyCrypt.sys driver as a temporary workaround until a patch is available. Restrict access to the IOCtl 0x8000c01c to minimize the risk of exploitation.