PT-2020-6995 · Evga · Evga Precision X1
Published
2020-08-11
·
Updated
2026-05-23
·
CVE-2020-14979
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EVGA Precision X1 versions through 1.0.6
winring0 project winring0 version 1.2.0
Description
The WinRing0.sys and WinRing0x64.sys drivers versions 1.2.0 in EVGA Precision X1 through 1.0.6 contain a flaw that allows local users, including those with low integrity, to read and write to arbitrary memory locations. This allows any user to gain NT AUTHORITYSYSTEM privileges by mapping DevicePhysicalMemory into the calling process. This issue has been actively exploited in cryptojacking campaigns, where it is used to deploy a custom XMRig miner and boost its hashrate. The malware spreads via USB drives, potentially infecting air-gapped systems. The vulnerability allows malicious programs to bypass system security measures.
Recommendations
Versions prior to 1.0.6 should be updated.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evga Precision X1