CVE-2019-8372: High severity lg lha.sys vulnerability
The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-8372?
CVE-2019-8372 is a vulnerability in the LHA.sys driver in LG Device Manager that allows low-privileged users to read and write arbitrary physical memory and elevate system privileges.
How does CVE-2019-8372 occur?
CVE-2019-8372 occurs because the LHA.sys driver in LG Device Manager exposes functionality that allows low-privileged users to exploit it via specially crafted IOCTL requests.
What is the severity of CVE-2019-8372?
CVE-2019-8372 has a severity level of high.
Which software is affected by CVE-2019-8372?
The affected software is LG Device Manager with LHA.sys driver version 1.1.1811.2101.
How can CVE-2019-8372 be fixed?
To fix CVE-2019-8372, users should apply the latest security updates provided by LG.