PT-2020-17054 · Devid Espenschied · Pc Analyser

Michal Poslušný

·

Published

2020-11-27

·

Updated

2021-07-21

·

CVE-2020-28921

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devid Espenschied PC Analyser versions through 4.10
Description An issue was discovered in the PCADRVX64.SYS kernel driver, which exposes IOCTL functionality. This allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs), potentially leading to arbitrary Ring-0 code execution and escalation of privileges.
Recommendations For Devid Espenschied PC Analyser versions through 4.10, consider disabling the PCADRVX64.SYS kernel driver until a patch is available to prevent low-privilege users from exploiting the IOCTL functionality. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-28921

Affected Products

Pc Analyser