CVE-2019-18845

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:patriotmemory:viper_rgb_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:patriotmemory:viper_rgb:-:*:*:*:*:*:*:*

Information

Published : 2019-11-09 10:15

Updated : 2020-03-18 12:15


NVD link : CVE-2019-18845

Mitre link : CVE-2019-18845


JSON object : View

CWE
CWE-269

Improper Privilege Management

Advertisement

dedicated server usa

Products Affected

patriotmemory

  • viper_rgb_firmware
  • viper_rgb