CVE ID | |
CVSS SCORE | 6.5, AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
Windows |
VULNERABILITY DETAILS |
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cdrom.sys driver. A crafted request with an IOCTL of 0x56C008 or 0x56C064 can trigger a memory corruption condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. |
ADDITIONAL DETAILS |
This vulnerability is being disclosed publicly without a patch in accordance with ZDI policies. 10/03/19 - ZDI reported the vulnerability to the vendor -- Mitigation: |
DISCLOSURE TIMELINE |
|
CREDIT | Meysam Firouzi of STAR Labs |