CVE-2018-19522: Input Validation
DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for partial input.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19522?
CVE-2018-19522 has not been assigned a CVSS score, but it poses a significant risk due to buffer overflow vulnerabilities in DriverAgent.
How do I fix CVE-2018-19522?
To mitigate CVE-2018-19522, update DriverAgent to the latest version or remove it from your system.
What software is affected by CVE-2018-19522?
CVE-2018-19522 specifically affects DriverAgent version 2.2015.7.14 which includes DrvAgent64.sys version 1.0.0.1.
What type of attack is possible via CVE-2018-19522?
CVE-2018-19522 could allow an authenticated attacker to execute arbitrary code in kernel mode due to improper handling of IOCTL calls.
Is there a known exploit for CVE-2018-19522?
As of now, there is no public information regarding a specific exploit for CVE-2018-19522.