CVE-2023-52271: Medium severity Topazevolution Antifraud vulnerability
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wsftprm.sys kernel driver 2.0.0.0 (Topaz Antifraud)from your environment.Uninstall or disable the wsftprm.sys kernel driver (version 2.0.0.0) or uninstall Topaz/Topazevolution Antifraud from affected systems until the vendor provides a patch.
- Compensating control
Isolate systems running Topaz/Topazevolution Antifraud and restrict access so that low-privileged users cannot interact with the driver (apply host/network isolation, firewall or endpoint controls to limit untrusted user access) until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52271?
CVE-2023-52271 is considered a high severity vulnerability due to its ability to allow low-privileged attackers to terminate protected processes.
How do I fix CVE-2023-52271?
To fix CVE-2023-52271, update the Topaz Antifraud software to a version above 2.0.0.0 when it is available.
Who is impacted by CVE-2023-52271?
All users of Topaz Antifraud version 2.0.0.0 or below are impacted by CVE-2023-52271.
What type of attack does CVE-2023-52271 facilitate?
CVE-2023-52271 facilitates an attack where low-privileged users can terminate any Protected Process Light process.
What component is vulnerable in CVE-2023-52271?
The vulnerable component in CVE-2023-52271 is the wsftprm.sys kernel driver version 2.0.0.0.