PT-2019-13094 · Toaruos · Toaruos

Published

2019-06-29

·

Updated

2022-09-29

·

CVE-2019-13047

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ToaruOS versions prior to 1.10.10
Description The issue is related to incorrect access control in the sys sysfunc case 9 for TOARU SYS FUNC SETHEAP, allowing arbitrary kernel pages to be mapped into user land. This can lead to root access.
Recommendations For versions prior to 1.10.10, update to version 1.10.10 or later to resolve the issue.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2019-13047

Affected Products

Toaruos