PT-2021-8200 · Crucial · Ballistix Mod Utility

Paolo Stagno

+1

·

Published

2021-09-29

·

Updated

2024-11-20

·

CVE-2021-41285

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ballistix MOD Utility versions 2.0.2.5 and earlier
Description The issue is related to a privilege escalation vulnerability in the MODAPI.sys driver component. It is triggered by sending a specific IOCTL request, allowing low-privileged users to directly interact with physical memory via the MmMapIoSpace function call, which maps physical memory into a virtual address space. This could enable attackers to achieve local privilege escalation to NT AUTHORITYSYSTEM. The vulnerability is associated with inadequate access control in the MmMapIoSpace function.
Recommendations For Ballistix MOD Utility versions 2.0.2.5 and earlier, as a temporary workaround, consider disabling the MmMapIoSpace function until a patch is available. Restrict access to the MODAPI.sys driver component to minimize the risk of exploitation. Avoid using the IOCTL request that triggers the vulnerability in the affected driver component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-11108
CVE-2021-41285

Affected Products

Ballistix Mod Utility