CVE-2018-7250: Infoleak
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7250?
CVE-2018-7250 is a vulnerability found in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc.
What is the severity of CVE-2018-7250?
CVE-2018-7250 has a severity rating of 5.5 (Medium).
What systems are affected by CVE-2018-7250?
Microsoft Windows 7, Windows 8, Windows 8.1, and Windows Vista are affected by CVE-2018-7250, as well as Tivo Safedisc.
How can a local unprivileged attacker exploit CVE-2018-7250?
A local unprivileged attacker can exploit CVE-2018-7250 by utilizing an uninitialized kernel pool allocation in IOCTL 0xCA002813 to leak 16 bits of uninitialized kernel stack memory.
Where can I find more information about CVE-2018-7250?
You can find more information about CVE-2018-7250 at the following reference: https://github.com/Elvin9/SecDrvPoolLeak/blob/master/README.md