PT-2018-10061 · Asrock · Restarttouefi+3

Diego Juarez

·

Published

2018-10-30

·

Updated

2019-10-03

·

CVE-2018-10712

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASRock RGBLED versions prior to 1.0.35.1 A-Tuning versions prior to 3.0.210 F-Stream versions prior to 3.0.210 RestartToUEFI versions prior to 1.0.6.2
Description The issue concerns the exposure of functionality to read/write data from/to IO ports by low-level drivers in several software products. This could potentially be leveraged to run code with elevated privileges.
Recommendations For ASRock RGBLED versions prior to 1.0.35.1, update to version 1.0.35.1 or later. For A-Tuning versions prior to 3.0.210, update to version 3.0.210 or later. For F-Stream versions prior to 3.0.210, update to version 3.0.210 or later. For RestartToUEFI versions prior to 1.0.6.2, update to version 1.0.6.2 or later.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10712

Affected Products

A-Tuning
Asrock Rgbled
F-Stream
Restarttouefi