PT-2020-11236 · Finalwire · Aida64

Ryan Warns

·

Published

2020-03-25

·

Updated

2020-04-01

·

CVE-2019-7244

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AIDA64 versions prior to 5.99
Description An issue was discovered in kerneld.sys. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x80112084 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
Recommendations For versions prior to 5.99, update to version 5.99 or later to resolve the issue. As a temporary workaround, consider restricting access to the kerneld.sys driver to minimize the risk of exploitation. Avoid using the IOCTL 0x80112084 instruction in the affected driver until the issue is resolved.

Exploit

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7244

Affected Products

Aida64