CVE-2017-14153
Last modified
CVE-2017-14153 is a vulnerability of currently unknown severity. This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. EPSS estimates a 1.82% chance of exploitation in the next 30 days.
Description
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x953824b7 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in a kernel pool overflow. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jungo | Windriver | <= 12.5.1 |
References
- http://packetstormsecurity.com/files/144046/Jungo-DriverWizard-WinDrive-Overflow.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42624/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/144046/Jungo-DriverWizard-WinDrive-Overflow.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42624/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14153?
How severe is CVE-2017-14153?
How do I fix CVE-2017-14153?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14145HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\contro…
- CVE-2017-14146HelpDEZk 1.1.1 allows remote authenticated users to execute …
- CVE-2017-14147An issue was discovered on FiberHome User End Routers Bearin…
- CVE-2017-14149GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference i…
- CVE-2017-14151An off-by-one error was discovered in opj_tcd_code_block_enc…8.8
- CVE-2017-14152A mishandled zero case was discovered in opj_j2k_set_cinema_…8.8
- CVE-2017-14156The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_ba…
- CVE-2017-14158Scrapy 1.4 allows remote attackers to cause a denial of serv…
- CVE-2017-14159slapd in OpenLDAP 2.4.45 and earlier creates a PID file afte…4.7
- CVE-2017-14160The bark_noise_hybridmp function in psy.c in Xiph.Org libvor…8.8
- CVE-2017-14163An issue was discovered in Mahara before 15.04.14, 16.x befo…
- CVE-2017-14164A size-validation issue was discovered in opj_j2k_write_sot …8.8
Are you affected by CVE-2017-14153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
