An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the driver's device object and issue IOCTLs to read or write to arbitrary physical memory locations (or call an arbitrary address), leading to execution of arbitrary code. This is associated with 0x226040, 0x226044, and 0x226000.
References
Link | Resource |
---|---|
https://nephosec.com/biostar-exploit/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-12-31 22:15
Updated : 2022-01-12 07:23
NVD link : CVE-2021-44852
Mitre link : CVE-2021-44852
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
biostar
- racing_gt_evo