PT-2020-13060 · Ati · Atillk64.Sys

Jesse Michael

+1

·

Published

2020-04-27

·

Updated

2025-11-21

·

CVE-2020-12138

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions atillk64.sys version 5.11.9.0
Description The issue allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of the calling process. This could enable low-privileged users to achieve NT AUTHORITYSYSTEM privileges via a DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages.
Recommendations For atillk64.sys version 5.11.9.0, consider restricting access to the driver routines MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, and MmMapLockedPages to prevent low-privileged users from achieving NT AUTHORITYSYSTEM privileges. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-12138

Affected Products

Atillk64.Sys