CVE-2008-7211
CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not create a Functional Device Object (FDO) to prevent user-moade access to the Physical Device Object (PDO), which…
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not create a Functional Device Object (FDO) to prevent user-moade access to the Physical Device Object (PDO), which allows local users to gain SYSTEM privileges via a crafted IRP request that dereferences a NULL FsContext pointer.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- soundblaster/ensoniq pci es1371 wdm driver
- Source
- cve@mitre.org
References
- http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=54
- http://www.securityfocus.com/archive/1/485848/100/200/threaded
- http://www.securityfocus.com/bid/27179Exploit
- http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=54
- http://www.securityfocus.com/archive/1/485848/100/200/threaded
- http://www.securityfocus.com/bid/27179Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.