PT-2023-3076 · Unknown · Foxboro.Sys

Published

2023-06-13

·

Updated

2023-06-22

·

CVE-2023-2569

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxboro.sys driver (affected versions not specified)
Description A CWE-787: Out-of-Bounds Write issue exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. The exploitation of this issue may allow an attacker to execute arbitrary code by sending a special IOCTL call.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-03158
CVE-2023-2569

Affected Products

Foxboro.Sys