PT-2020-13586 · Nzxt · Nzxt Cam
Published
2020-12-17
·
Updated
2023-01-20
·
CVE-2020-13509
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NZXT CAM version 4.8.0
Description
An information disclosure issue exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality. A specially crafted I/O request packet (IRP) using the IRP
0x9c4060cc gives a low privilege user direct access to the IN instruction at an elevated privilege level. This could allow for information leakage of sensitive data. An attacker can send a malicious IRP to trigger this issue.Recommendations
For NZXT CAM version 4.8.0, consider disabling the WinRing0x64 Driver Privileged I/O Read IRPs functionality until a patch is available to prevent potential information leakage. Restrict access to the
IN instruction to minimize the risk of exploitation. Avoid using the IRP 0x9c4060cc in the affected functionality until the issue is resolved.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nzxt Cam