CVE-2023-1677
A vulnerability was found in DriverGenius 9.70.0.346.
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in DriverGenius 9.70.0.346. It has been rated as problematic. Affected by this issue is the function 0x9c40a0c8/0x9c40a0dc/0x9c40a0e0/0x9c40a0d8/0x9c4060d4/0x9c402004/0x9c402088/0x9c40208c/0x9c4060d0/0x9c4060cc/0x9c4060c4/0x9c402084 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-224234 is the identifier assigned to this vulnerability.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.22% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- drivergenius/drivergenius
- Source
- cna@vuldb.com
References
- https://drive.google.com/file/d/1C7afiLbOOLuYZVeeslPW3AdNeOIwUea9/viewThird Party Advisory
- https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/CVE-2023-1677Third Party Advisory
- https://vuldb.com/?ctiid.224234Third Party Advisory
- https://vuldb.com/?id.224234Third Party Advisory
- https://drive.google.com/file/d/1C7afiLbOOLuYZVeeslPW3AdNeOIwUea9/viewThird Party Advisory
- https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/CVE-2023-1677Third Party Advisory
- https://vuldb.com/?ctiid.224234Third Party Advisory
- https://vuldb.com/?id.224234Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.