PT-2024-25164 · Insyde · Seg Windows Driver

Published

2024-05-22

·

Updated

2024-08-15

·

CVE-2024-33228

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Insyde Software Corp SEG Windows Driver version 100.00.07.02
Description An issue in the component segwindrvx64.sys allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Recommendations For version 100.00.07.02, consider disabling the vulnerable component segwindrvx64.sys until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-33228

Affected Products

Seg Windows Driver