CVE-2024-55414: Command Injection
A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
Other sources
Microsoft is aware of vulnerabilities in the third party Motorola Soft Modem drivers that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of smserl64.sys and smserial.sys drivers. The drivers have been removed in the January cumulative update. Soft modem hardware dependent on these specific drivers will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.
— Microsoft
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55414?
CVE-2024-55414 is classified as a high severity vulnerability due to its potential for privilege escalation and code execution.
How do I fix CVE-2024-55414?
To fix CVE-2024-55414, update the Motorola SM56 Modem WDM Driver to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-55414?
Users of the Motorola SM56 Modem WDM Driver version 6.12.23.0 are affected by CVE-2024-55414.
What exploits can be performed using CVE-2024-55414?
CVE-2024-55414 can be exploited for privilege escalation, allowing low-privileged users to execute code with higher privileges.
What is the impact of CVE-2024-55414?
The impact of CVE-2024-55414 includes potential information disclosure and unauthorized access to system resources.