PoC Index

CVE-2019-8372

HIGH 7.0EPSS 0.5%

The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.

CVSS v3.0
7.0 HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS
0.54% chance of exploitation in the next 30 days, 43th percentile
Published
2019-02-18
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related