Vulnerability Description
Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via MmMapIoSpace) and IOCTL 0x9c406490 (via ZwMapViewOfSection).
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.marvintest.com/Downloads.aspx?prodId=12&search=package
- https://www.marvintest.com/KnowledgeBase/KBArticle.aspx?ID=362
- https://www.marvintest.com/Downloads.aspx?prodId=12&search=package
- https://www.marvintest.com/KnowledgeBase/KBArticle.aspx?ID=362
FAQ
What is CVE-2024-36054?
CVE-2024-36054 is a vulnerability with a CVSS score of 7.4 (HIGH). Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via MmMapIoSpace) a...
How severe is CVE-2024-36054?
CVE-2024-36054 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36054?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.