vendor:
MaxxAudio Drivers
by:
Mike Siegel
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: MaxxAudio Drivers
Affected Version From: 1.6.2.0
Affected Version To: 1.6.2.0
Patch Exists: YES
Related CWE: CVE-2019-15084
CPE: a:maxxaudio:maxxaudio_drivers
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win 10 64 bit
2019
MaxxAudio Drivers WavesSysSvc64.exe File Permissions SYSTEM Privilege Escalation
MaxxAudio licenses their driver technology to OEMs and is commonly installed on Dell Laptops (and others) as part of other driver installations. MaxxAudio drivers version 1.6.2.0 install with incorrect file permissions. As a result a local attacker can escalate to SYSTEM level privileges. Dell PSIRT has acknowledged the issue and advises updating to a supported driver.
Mitigation:
Update to a supported driver.