CVE-2018-10711: Input Validation
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10711?
CVE-2018-10711 is rated as having high severity due to the potential for arbitrary code execution.
How do I fix CVE-2018-10711?
To fix CVE-2018-10711, update the ASRock drivers affected to their latest versions: A-Tuning to v3.0.210, F-Stream to v3.0.210, RestartToUEFI to v1.0.6.2, and RGBLED to v1.0.35.1.
What are the vulnerable ASRock applications for CVE-2018-10711?
The vulnerable ASRock applications for CVE-2018-10711 include ASRock RGBLED versions prior to 1.0.35.1, A-Tuning versions prior to 3.0.210, F-Stream versions prior to 3.0.210, and RestartToUEFI versions prior to 1.0.6.2.
What types of vulnerabilities does CVE-2018-10711 expose?
CVE-2018-10711 exposes vulnerabilities related to privilege escalation and arbitrary read/write access to Machine Specific Registers.
Can CVE-2018-10711 be exploited remotely?
CVE-2018-10711 typically requires local access to exploit, as it leverages low-level driver functionalities.