CVE-2020-9014: Medium severity epson iprojection vulnerability
In Epson iProjection v2.30, the driver file (EMPNSAU.sys) allows local users to cause a denial of service (BSOD) via crafted input to the virtual audio device driver with IOCTL 0x9C402402, 0x9C402406, or 0x9C40240A. \Device\EMPNSAUIO and \DosDevices\EMPNSAU are similarly affected.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-9014?
CVE-2020-9014 is a vulnerability in Epson iProjection v2.30 that allows local users to cause a denial of service (BSOD) by exploiting a driver file (EMP_NSAU.sys) with crafted input to the virtual audio device driver.
How can the vulnerability be exploited?
The vulnerability can be exploited by local users sending crafted input to the virtual audio device driver with specific IOCTL values.
What is the severity level of CVE-2020-9014?
The severity level of CVE-2020-9014 is medium with a CVSS score of 5.5.
How can I fix CVE-2020-9014?
To fix CVE-2020-9014, update Epson iProjection to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2020-9014?
More information about CVE-2020-9014 can be found at the following references: [Link1], [Link2], [Link3].