CVE-2018-8060
Last modified
CVE-2018-8060 is a vulnerability of currently unknown severity. HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or output buffer pointers are NULL or if these buffers' data are invalid, a NULL/invalid pointer access occurs, resulting in a Windows kernel panic aka Blue Screen. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or output buffer pointers are NULL or if these buffers' data are invalid, a NULL/invalid pointer access occurs, resulting in a Windows kernel panic aka Blue Screen. This affects IOCTLs higher than 0x85FE2600 with the HWiNFO32 symbolic device name.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hwinfo | Amd64 Kernel Driver | <= 8.98 |
References
- https://github.com/otavioarj/SIOCtlExploit, Third Party Advisory
- https://github.com/otavioarj/SIOCtlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-8060?
How severe is CVE-2018-8060?
How do I fix CVE-2018-8060?
Are you affected by CVE-2018-8060?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
