PT-2017-13980 · Cpuid · Cpu-Z
Published
2017-10-16
·
Updated
2017-11-07
·
CVE-2017-15303
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CPUID CPU-Z versions prior to 1.43
Description
The issue allows for an arbitrary memory write, resulting in elevation of privileges. This can occur when any program running on the local machine issues an ioctl call to the kernel-mode driver while CPU-Z is running. For example, this can be done through the
0x9C402430 ioctl call to drivers such as cpuz141 x64.sys.Recommendations
For versions prior to 1.43, update to version 1.43 or later to resolve the issue. As a temporary workaround, consider restricting access to the kernel-mode driver to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpu-Z