CVE-2023-1679
A vulnerability classified as critical was found in DriverGenius 9.70.0.346.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9C406104/0x9C40A108 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224236.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- drivergenius/drivergenius
- Source
- cna@vuldb.com
References
- https://drive.google.com/file/d/1Iz4VTUUVDveZlgtxN9WkvdygHkD1BUCr/viewThird Party Advisory
- https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/CVE-2023-1679Third Party Advisory
- https://vuldb.com/?ctiid.224236Third Party Advisory
- https://vuldb.com/?id.224236Third Party Advisory
- https://drive.google.com/file/d/1Iz4VTUUVDveZlgtxN9WkvdygHkD1BUCr/viewThird Party Advisory
- https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/CVE-2023-1679Third Party Advisory
- https://vuldb.com/?ctiid.224236Third Party Advisory
- https://vuldb.com/?id.224236Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.