CVE Vulnerabilities

CVE-2019-18845

Improper Privilege Management

Published: Nov 09, 2019 | Modified: Mar 18, 2020
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITYSYSTEM privileges, by mapping DevicePhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Viper_rgb_firmware Patriotmemory 1.0 (including) 1.0 (including)

Potential Mitigations

References