{"api_version":"1","generated_at":"2026-07-24T00:13:41+00:00","cve":"CVE-2020-36603","urls":{"html":"https://cve.report/CVE-2020-36603","api":"https://cve.report/api/cve/CVE-2020-36603.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-36603","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-36603"},"summary":{"title":"CVE-2020-36603","description":"The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-09-14 22:15:00","updated_at":"2022-09-20 16:59:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html","name":"https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html","refsource":"MISC","tags":[],"title":"Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/kkent030315/evil-mhyprot-cli","name":"https://github.com/kkent030315/evil-mhyprot-cli","refsource":"MISC","tags":[],"title":"GitHub - kkent030315/evil-mhyprot-cli: A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process.","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://web.archive.org/web/20211204031301/https://www.godeye.club/2021/05/20/001-disclosure-mhyprot.html","name":"https://web.archive.org/web/20211204031301/https://www.godeye.club/2021/05/20/001-disclosure-mhyprot.html","refsource":"MISC","tags":[],"title":"Disclosure: The Mhyprot Vulnerability - Genshin Impact | GodEye.club","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.vice.com/en/article/y3p35w/hackers-are-using-anti-cheat-in-genshin-impact-to-ransom-victims","name":"https://www.vice.com/en/article/y3p35w/hackers-are-using-anti-cheat-in-genshin-impact-to-ransom-victims","refsource":"MISC","tags":[],"title":"Hackers Are Using Anti-Cheat in 'Genshin Impact' to Ransom Victims","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/kagurazakasanae/Mhyprot2DrvControl","name":"https://github.com/kagurazakasanae/Mhyprot2DrvControl","refsource":"MISC","tags":[],"title":"GitHub - kagurazakasanae/Mhyprot2DrvControl: A lib that allows using mhyprot2 driver for enum process modules, r/w process memory and kill process.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-36603","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-36603","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"36603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hoyoverse","cpe5":"mhyprot2","cpe6":"1.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","DATE_PUBLIC":"2020-10-15T04:35:00.000Z","ID":"CVE-2020-36603","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges."}]},"generator":{"engine":"Vulnogram 0.0.9"},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/kkent030315/evil-mhyprot-cli","refsource":"MISC","url":"https://github.com/kkent030315/evil-mhyprot-cli"},{"name":"https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html","refsource":"MISC","url":"https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html"},{"name":"https://www.vice.com/en/article/y3p35w/hackers-are-using-anti-cheat-in-genshin-impact-to-ransom-victims","refsource":"MISC","url":"https://www.vice.com/en/article/y3p35w/hackers-are-using-anti-cheat-in-genshin-impact-to-ransom-victims"},{"name":"https://github.com/kagurazakasanae/Mhyprot2DrvControl","refsource":"MISC","url":"https://github.com/kagurazakasanae/Mhyprot2DrvControl"},{"name":"https://web.archive.org/web/20211204031301/https://www.godeye.club/2021/05/20/001-disclosure-mhyprot.html","refsource":"MISC","url":"https://web.archive.org/web/20211204031301/https://www.godeye.club/2021/05/20/001-disclosure-mhyprot.html"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-09-14 22:15:00","lastModifiedDate":"2022-09-20 16:59:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.6,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hoyoverse:mhyprot2:1.0.0.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}