PT-2025-47330 · Unknown+1 · Awesome Miner+2

Dreadsec

·

Published

2025-11-18

·

Updated

2025-12-31

·

CVE-2025-63602

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Awesome Miner versions through 11.2.4
Description A flaw exists in Awesome Miner that permits unauthorized read and write access to kernel memory and Model Specific Registers (MSRs), including LSTAR, even for users without administrative privileges. This is a result of an insecure implementation of WinRing0 (version 1.2.0.5, rebranded as IntelliBreeze.Maintenance.Service.sys) which has a deficient Discretionary Access Control List (DACL). This inadequate DACL allows non-privileged users to interact with the driver and, consequently, the kernel. Successful exploitation could lead to local privilege escalation, information disclosure, denial of service, and other potential consequences.
Recommendations Versions prior to 11.2.5 should be updated.

Exploit

Fix

Buffer Over-read

Weakness Enumeration

Related Identifiers

CVE-2025-63602

Affected Products

Awesome Miner
Intellibreeze.Maintenance.Service.Sys
Winring0