CVE-2020-36603
Summary
| CVE | CVE-2020-36603 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-14 22:15:00 UTC |
| Updated | 2022-09-20 16:59:00 UTC |
| Description | The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus | MISC | www.trendmicro.com | |
| GitHub - kkent030315/evil-mhyprot-cli: A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process. | MISC | github.com | |
| Disclosure: The Mhyprot Vulnerability - Genshin Impact | GodEye.club | MISC | web.archive.org | |
| Hackers Are Using Anti-Cheat in 'Genshin Impact' to Ransom Victims | MISC | www.vice.com | |
| GitHub - kagurazakasanae/Mhyprot2DrvControl: A lib that allows using mhyprot2 driver for enum process modules, r/w process memory and kill process. | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.