PoC Index

CVE-2018-8061

HIGH 7.1EPSS 0.4%

HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symbolic device name, resulting in direct physical memory read or write.

CVSS v3.0
7.1 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0
3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
EPSS
0.44% chance of exploitation in the next 30 days, 36th percentile
Published
2018-05-10
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related