CVE-2024-26507

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.
Configurations

No configuration.

History

21 Nov 2024, 09:02

Type Values Removed Values Added
References () https://belong2yourself.github.io/vulnerabilities/docs/AIDA/Elevation-of-Privileges/readme/ - () https://belong2yourself.github.io/vulnerabilities/docs/AIDA/Elevation-of-Privileges/readme/ -

03 Jul 2024, 01:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-1286
Summary
  • (es) Un problema en FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 y anteriores permite a un atacante local escalar privilegios a través de la llamada DeviceIoControl asociada con los componentes MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPaggedPool o MmMapLockedPages.

10 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-10 16:15

Updated : 2024-11-21 09:02


NVD link : CVE-2024-26507

Mitre link : CVE-2024-26507

CVE.ORG link : CVE-2024-26507


JSON object : View

Products Affected

No product.

CWE
CWE-1286

Improper Validation of Syntactic Correctness of Input