PT-2024-25791 · Sisoftware · Sisoftware Sandra

H0Mbre

+1

·

Published

2024-06-10

·

Updated

2024-07-03

·

CVE-2024-34332

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiSoftware SANDRA versions prior to v31.67
Description An issue in SiSoftware SANDRA allows an attacker to escalate privileges via a crafted buffer sent to the Kernel Driver using the DeviceIoControl Windows API.
Recommendations For SiSoftware SANDRA versions prior to v31.67, update to a version newer than v31.66 to resolve the issue. As a temporary workaround, consider restricting access to the Kernel Driver to minimize the risk of exploitation.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-34332

Affected Products

Sisoftware Sandra