PT-2024-25163 · Nicomsoft · Nicomsoft Wini2C/Ddc

Published

2024-05-22

·

Updated

2024-08-21

·

CVE-2024-33227

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nicomsoft WinI2C/DDC version 3.7.4.0
Description An issue in the component ddcdrv.sys allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Recommendations For version 3.7.4.0, consider disabling the ddcdrv.sys component until a patch is available to prevent exploitation. Restrict access to the vulnerable component to minimize the risk of privilege escalation and arbitrary code execution.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-33227

Affected Products

Nicomsoft Wini2C/Ddc