PT-2020-13118 · G.Skill · G.Skill Trident Z Lighting Control
Hashim Jawad
·
Published
2020-04-29
·
Updated
2025-09-08
·
CVE-2020-12446
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
G.SKILL Trident Z Lighting Control versions 1.00.08 and earlier
Description
The issue allows local non-privileged users to access sensitive operations, including mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports. This exposure leads to privilege escalation to NT AUTHORITYSYSTEM.
Recommendations
For versions 1.00.08 and earlier, consider disabling the ene.sys driver as a temporary workaround to minimize the risk of exploitation. Restrict access to the affected driver to prevent local non-privileged users from escalating privileges to NT AUTHORITYSYSTEM. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
G.Skill Trident Z Lighting Control