CVE-2019-18845

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:patriotmemory:viper_rgb_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:patriotmemory:viper_rgb:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:33

Type Values Removed Values Added
References () https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-012.md - () https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-012.md -

Information

Published : 2019-11-09 18:15

Updated : 2024-11-21 04:33


NVD link : CVE-2019-18845

Mitre link : CVE-2019-18845

CVE.ORG link : CVE-2019-18845


JSON object : View

Products Affected

patriotmemory

  • viper_rgb_firmware
  • viper_rgb
CWE
CWE-269

Improper Privilege Management