PT-2020-11236 · Finalwire · Aida64
Ryan Warns
·
Published
2020-03-25
·
Updated
2020-04-01
·
CVE-2019-7244
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AIDA64 versions prior to 5.99
Description
An issue was discovered in kerneld.sys. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x80112084 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
Recommendations
For versions prior to 5.99, update to version 5.99 or later to resolve the issue. As a temporary workaround, consider restricting access to the kerneld.sys driver to minimize the risk of exploitation. Avoid using the IOCTL 0x80112084 instruction in the affected driver until the issue is resolved.
Exploit
Fix
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aida64