PT-2024-22931 · Bluerisc · Bluerisc Windowsscope Cyber Forensics

Dru1D-Foofus

·

Published

2024-05-13

·

Updated

2024-08-01

·

CVE-2024-29513

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BlueRiSC WindowsSCOPE Cyber Forensics versions prior to 3.3
Description The issue is related to an improper DACL being applied to the device created by the briscKernelDriver.sys driver, allowing a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition.
Recommendations For versions prior to 3.3, update to version 3.3 or later to resolve the issue.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-29513

Affected Products

Bluerisc Windowsscope Cyber Forensics