vendor:
Ambient Link Driver
by:
Matteo Malvica
7.8
CVSS
HIGH
Kernel Stack Based Buffer Overflow
119
CWE
Product Name: Ambient Link Driver
Affected Version From: 1.0.0.8
Affected Version To: 1.0.0.8
Patch Exists: YES
Related CWE: CVE-2020-17382
CPE: a:msi:ambient_link_driver:1.0.0.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 1709
2020
MSI Ambient Link Driver 1.0.0.8 – Local Privilege Escalation
MSI Ambient Link Driver 1.0.0.8 contains a kernel stack based buffer overflow vulnerability which can be exploited by a local attacker to gain elevated privileges. The vulnerability exists in the MSIO64.sys driver, which fails to properly validate user-supplied input when handling IOCTL 0x222040. An attacker can send a specially crafted IOCTL request to the vulnerable driver, which can be used to overwrite a function pointer on the stack and gain arbitrary code execution in kernel mode.
Mitigation:
Update to the latest version of MSI Ambient Link Driver 1.0.0.8