PT-2020-13118 · G.Skill · G.Skill Trident Z Lighting Control

Hashim Jawad

·

Published

2020-04-29

·

Updated

2025-09-08

·

CVE-2020-12446

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions G.SKILL Trident Z Lighting Control versions 1.00.08 and earlier
Description The issue allows local non-privileged users to access sensitive operations, including mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports. This exposure leads to privilege escalation to NT AUTHORITYSYSTEM.
Recommendations For versions 1.00.08 and earlier, consider disabling the ene.sys driver as a temporary workaround to minimize the risk of exploitation. Restrict access to the affected driver to prevent local non-privileged users from escalating privileges to NT AUTHORITYSYSTEM. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2020-12446

Affected Products

G.Skill Trident Z Lighting Control