header-logo
Suggest Exploit
vendor:
Creative Ensoniq PCI ES1371 WDM drivers
by:
SecurityFocus
7.2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Creative Ensoniq PCI ES1371 WDM drivers
Affected Version From: 5.1.3612.0
Affected Version To: 5.1.3612.0
Patch Exists: Yes
Related CWE: N/A
CPE: o:creative_technology:creative_ensoniq_pci_es1371_wdm_drivers
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows Vista, VMware Server, VMware Workstation
2008

Creative Ensoniq PCI ES1371 WDM drivers Local Privilege Escalation Vulnerability

Creative Ensoniq PCI ES1371 WDM drivers are prone to a local privilege-escalation vulnerability. Successful exploits allow local users to execute arbitrary machine code with kernel-level privileges, facilitating the complete compromise of affected computers. This issue occurs when the vulnerable driver is running in a Microsoft Windows Vista environment. This occurs in VMware Server and Workstation environments when running Microsoft Vista guest operating systems with sound enabled.

Mitigation:

Upgrade to the latest version of the Creative Ensoniq PCI ES1371 WDM drivers.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/27179/info

Creative Ensoniq PCI ES1371 WDM drivers are prone to a local privilege-escalation vulnerability.

Successful exploits allow local users to execute arbitrary machine code with kernel-level privileges, facilitating the complete compromise of affected computers.

This issue occurs when the vulnerable driver is running in a Microsoft Windows Vista environment. This occurs in VMware Server and Workstation environments when running Microsoft Vista guest operating systems with sound enabled.

This issue affects 'es1371mp.sys' 5.1.3612.0. Given the nature of the issue, other device drivers and versions may also be vulnerable, but this has not been confirmed. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30999.zip