CVE-2019-18845
Summary
| CVE | CVE-2019-18845 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-09 18:15:00 UTC |
| Updated | 2020-03-18 19:15:00 UTC |
| Description | The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Patriotmemory | Viper Rgb | - | All | All | All |
| Hardware | Patriotmemory | Viper Rgb | - | All | All | All |
| Operating System | Patriotmemory | Viper Rgb Firmware | 1.0 | All | All | All |
| Operating System | Patriotmemory | Viper Rgb Firmware | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories/ACTIVE-2019-012.md at master · active-labs/Advisories · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.