PT-2020-13060 · Ati · Atillk64.Sys
Jesse Michael
+1
·
Published
2020-04-27
·
Updated
2025-11-21
·
CVE-2020-12138
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
atillk64.sys version 5.11.9.0
Description
The issue allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of the calling process. This could enable low-privileged users to achieve NT AUTHORITYSYSTEM privileges via a DeviceIoControl call associated with
MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages.Recommendations
For atillk64.sys version 5.11.9.0, consider restricting access to the driver routines
MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, and MmMapLockedPages to prevent low-privileged users from achieving NT AUTHORITYSYSTEM privileges.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atillk64.Sys