CVE-2017-14075: High severity jungo windriver vulnerability
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x953824a7 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in an out-of-bounds write condition. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14075?
CVE-2017-14075 is considered a high-severity vulnerability due to its potential to allow local privilege escalation.
How do I fix CVE-2017-14075?
To fix CVE-2017-14075, update Jungo WinDriver to version 12.5.1 or later.
Who is affected by CVE-2017-14075?
CVE-2017-14075 affects users of Jungo WinDriver version 12.4.0 and earlier.
What type of attack does CVE-2017-14075 enable?
CVE-2017-14075 enables local attackers to escalate their privileges on impacted systems.
What must an attacker have to exploit CVE-2017-14075?
An attacker must first execute low-privileged code on the target system to exploit CVE-2017-14075.