CVE-2018-8061
HIGH 7.1EPSS 0.4%
HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symbolic device name, resulting in direct physical memory read or write.
- CVSS v3.0
- 7.1 HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - CVSS v2.0
- 3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N - EPSS
- 0.44% chance of exploitation in the next 30 days, 36th percentile
- Published
- 2018-05-10
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- otavioarj/SIOCtl4★ · 2018-05-09