HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symbolic device name, resulting in direct physical memory read or write.
References
Link | Resource |
---|---|
https://github.com/otavioarj/SIOCtl | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-05-09 20:29
Updated : 2018-06-13 06:42
NVD link : CVE-2018-8061
Mitre link : CVE-2018-8061
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
hwinfo
- amd64_kernel_driver