CVE-2024-26507

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.
Configurations

No configuration.

History

03 Jul 2024, 01:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) Un problema en FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 y anteriores permite a un atacante local escalar privilegios a través de la llamada DeviceIoControl asociada con los componentes MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPaggedPool o MmMapLockedPages.
CWE CWE-1286

10 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-10 16:15

Updated : 2024-07-03 01:49


NVD link : CVE-2024-26507

Mitre link : CVE-2024-26507

CVE.ORG link : CVE-2024-26507


JSON object : View

Products Affected

No product.

CWE
CWE-1286

Improper Validation of Syntactic Correctness of Input