PT-2019-12529 · Softether · See.Sys+1
Downwithup
·
Published
2019-07-29
·
Updated
2021-08-27
·
CVE-2019-11868
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SoftEther VPN Server versions up to 4.29
See.sys up to version 4.25
Description
The issue allows a user to call an IOCTL, specifying any kernel address to which arbitrary bytes are written. This can potentially lead to unauthorized access and modification of kernel memory.
Recommendations
For SoftEther VPN Server versions up to 4.29, update See.sys to a version newer than 4.25 to resolve the issue.
For See.sys up to version 4.25, consider restricting access to the IOCTL function until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
See.Sys
Softether Vpn Server