CVE-2020-11520

The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory addresses because the IOCTL dispatcher lacks pointer validation. Exploiting this vulnerability results in privileged code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:winmagic:securedoc:*:*:*:*:*:*:*:*

History

03 May 2022, 13:59

Type Values Removed Values Added
CWE CWE-269 CWE-119
References (CONFIRM) https://www.winmagic.com/support/release-notes/securedoc-v8-5-sr2/ - Vendor Advisory (CONFIRM) https://www.winmagic.com/support/release-notes/securedoc-v8-5-sr2/ - Release Notes, Vendor Advisory
References (CONFIRM) https://www.winmagic.com/support/release-notes/securedoc-v8-5-sr2-hf1 - (CONFIRM) https://www.winmagic.com/support/release-notes/securedoc-v8-5-sr2-hf1 - Release Notes, Vendor Advisory

Information

Published : 2020-06-22 18:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-11520

Mitre link : CVE-2020-11520

CVE.ORG link : CVE-2020-11520


JSON object : View

Products Affected

winmagic

  • securedoc
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer