Vulnerability Description
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ioctl 0x9C402430 call to the kernel-mode driver (e.g., cpuz141_x64.sys for version 1.41).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cpuid | Cpu-Z | <= 1.42 |
Related Weaknesses (CWE)
References
- https://github.com/akayn/Bugs/blob/master/CPUID/CVE-2017-15303/README.mdThird Party Advisory
- https://github.com/akayn/Bugs/blob/master/CPUID/CVE-2017-15303/README.mdThird Party Advisory
FAQ
What is CVE-2017-15303?
CVE-2017-15303 is a vulnerability with a CVSS score of 7.8 (HIGH). In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ...
How severe is CVE-2017-15303?
CVE-2017-15303 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15303?
Check the references section above for vendor advisories and patch information. Affected products include: Cpuid Cpu-Z.