The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory addresses because the IOCTL dispatcher lacks pointer validation. Exploiting this vulnerability results in privileged code execution.
References
Link | Resource |
---|---|
https://www.winmagic.com/support/release-notes/securedoc-v8-5-sr2/ | Release Notes Vendor Advisory |
https://www.winmagic.com/support/release-notes/securedoc-v8-5-sr2-hf1 | Release Notes Vendor Advisory |
Configurations
Information
Published : 2020-06-22 11:15
Updated : 2022-05-03 06:59
NVD link : CVE-2020-11520
Mitre link : CVE-2020-11520
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
winmagic
- securedoc