PT-2020-17054 · Devid Espenschied · Pc Analyser
Michal Poslušný
·
Published
2020-11-27
·
Updated
2021-07-21
·
CVE-2020-28921
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Devid Espenschied PC Analyser versions through 4.10
Description
An issue was discovered in the PCADRVX64.SYS kernel driver, which exposes IOCTL functionality. This allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs), potentially leading to arbitrary Ring-0 code execution and escalation of privileges.
Recommendations
For Devid Espenschied PC Analyser versions through 4.10, consider disabling the PCADRVX64.SYS kernel driver until a patch is available to prevent low-privilege users from exploiting the IOCTL functionality.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pc Analyser