PT-2021-11582 · Unknown · Drivergenius
Shuaibing Lu
·
Published
2021-01-03
·
Updated
2021-01-07
·
CVE-2020-28841
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
DriverGenius version 9.61.3708.3054
Description:
The issue allows attackers to cause a system crash via the ioctl command 0x9c402000 to the API endpoint ".MyDrivers0 0 1".
Recommendations:
For DriverGenius version 9.61.3708.3054, consider disabling the
MyDrivers64.sys driver until a patch is available to prevent system crashes via the ioctl command. Restrict access to the .MyDrivers0 0 1 endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drivergenius