PT-2020-20738 · Patriot · Patriot Viper Rgb Driver

Published

2020-03-06

·

Updated

2021-07-21

·

CVE-2020-9756

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Patriot Viper RGB Driver version 1.1 and prior
Description The issue exposes IOCTL and allows insufficient access control, potentially enabling a local user with low privileges to read or write data from or to an IO port. This could be leveraged to run code with elevated privileges. The IOCTL Codes 0x80102050 and 0x80102054 are specifically affected, allowing a local user to read/write 1/2/4 bytes from or to an IO port.
Recommendations For Patriot Viper RGB Driver version 1.1 and prior, consider restricting access to the IOCTL codes 0x80102050 and 0x80102054 as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-9756

Affected Products

Patriot Viper Rgb Driver