PT-2018-15314 · Microsoft+1 · Ssdt.Sys+1

Published

2018-12-23

·

Updated

2018-12-31

·

CVE-2018-20331

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Antiy AVL ATool version 1.0.0.22
Description The issue is caused by a failure to properly validate the length of user-supplied data in the processing of IOCTL 0x80002004 by the ssdt.sys kernel driver. This can lead to a Kernel Pool Buffer Overflow, allowing an attacker to execute arbitrary code in the context of the kernel, potentially resulting in privilege escalation. A failed exploit could lead to denial of service. The attacker must first obtain the ability to execute low-privileged code on the target system.
Recommendations For Antiy AVL ATool version 1.0.0.22, as a temporary workaround, consider restricting access to the ssdt.sys kernel driver to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20331

Affected Products

Antiy Avl Atool
Ssdt.Sys