PT-2022-26222 · Wfs · Heavenburnsred

Doranekosystems

+1

·

Published

2022-12-20

·

Updated

2025-03-26

·

CVE-2022-42046

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WFS, Inc HeavenBurnsRed version 2020.3.15.7141260
Description The issue allows for local privilege escalation through specially crafted IOCTL requests to wfshbr64.sys and wfshbr32.sys drivers. This can enable an arbitrary user to gain elevated privileges. The estimated number of potentially affected devices and details about real-world incidents where this issue was exploited are not provided.
Recommendations For WFS, Inc HeavenBurnsRed version 2020.3.15.7141260, consider updating to a newer version that uses ObRegisterCallbacks instead of PPL to mitigate the risk of local privilege escalation. As a temporary workaround, consider restricting access to the wfshbr64.sys and wfshbr32.sys drivers until a patch is available. Avoid using the vulnerable IOCTL requests to the wfshbr64.sys and wfshbr32.sys drivers until the issue is resolved.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-42046

Affected Products

Heavenburnsred