First published: Tue Dec 18 2018(Updated: )
DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for partial input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Azure VM Agents | =2.2015.7.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19522 has not been assigned a CVSS score, but it poses a significant risk due to buffer overflow vulnerabilities in DriverAgent.
To mitigate CVE-2018-19522, update DriverAgent to the latest version or remove it from your system.
CVE-2018-19522 specifically affects DriverAgent version 2.2015.7.14 which includes DrvAgent64.sys version 1.0.0.1.
CVE-2018-19522 could allow an authenticated attacker to execute arbitrary code in kernel mode due to improper handling of IOCTL calls.
As of now, there is no public information regarding a specific exploit for CVE-2018-19522.