PT-2020-18798 · F5 · Big-Ip Edge Client
Published
2020-05-12
·
Updated
2020-05-14
·
CVE-2020-5898
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BIG-IP Edge Client versions 7.1.5 through 7.1.9
Description
The BIG-IP Edge Client Windows Stonewall driver does not properly sanitize pointers received from userland, allowing a local user on the Windows client system to send crafted
DeviceIoControl requests to the .urvpndrv device. This can cause the Windows kernel to crash.Recommendations
For versions 7.1.5 through 7.1.9, consider disabling the Stonewall driver as a temporary workaround until a patch is available. Restrict access to the
.urvpndrv device to minimize the risk of exploitation. Avoid using the DeviceIoControl requests to the vulnerable device until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Big-Ip Edge Client