目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2023-1679— DriverGenius 缓冲区错误漏洞

CVSS 5.3 · Medium EPSS 0.32% · P25

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-1679の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
DriverGenius IOCTL mydrivers64.sys 0x9C40A108 memory corruption
ソース: CVE Program / CVE List V5
脆弱性説明
A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9C406104/0x9C40A108 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224236.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
ソース: CVE Program / CVE List V5
脆弱性タイプ
内存缓冲区边界内操作的限制不恰当
ソース: CVE Program / CVE List V5
脆弱性タイトル
DriverGenius 缓冲区错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Cmcm Drivergenius(驱动精灵)是中国北京猎豹移动科技有限公司(Cmcm)公司的一个用于Windows系统解决驱动适配更新、下载的软件。 DriverGenius 9.70.0.346版本存在安全漏洞.攻击者利用该漏洞导致内存损坏。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
-DriverGenius 9.70.0.346 -

II. CVE-2023-1679の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-1679のインテリジェンス情報

登录查看更多情报信息。

CVE-2023-1679 厂商安全公告 (1)

CVE-2023-1679 其他参考 (2)

Same Patch Batch · n/a · 2023-03-28 · 28 CVEs total

CVE-2023-16767.8 HIGHDriverGenius IOCTL mydrivers64.sys 0x9C402088 memory corruption
CVE-2023-16775.5 MEDIUMDriverGenius IOCTL mydrivers64.sys 0x9c402084 denial of service
CVE-2023-16785.3 MEDIUMDriverGenius IOCTL mydrivers64.sys 0x9C40A0E0 memory corruption
CVE-2023-27821Databasir 安全漏洞
CVE-2023-27701MuYuCMS 安全漏洞
CVE-2023-27700MuYuCMS 路径遍历漏洞
CVE-2023-27247Cynet Client Agent 安全漏洞
CVE-2023-27246MK-Auth 代码问题漏洞
CVE-2023-27232TOTOLINK A7100RU 命令注入漏洞
CVE-2023-27231TOTOLINK A7100RU 命令注入漏洞
CVE-2023-27229TOTOLINK A7100RU 命令注入漏洞
CVE-2023-27008ATutor 跨站脚本漏洞
CVE-2023-26923Musescore 缓冲区错误漏洞
CVE-2023-26071MCUBO ICT 安全漏洞
CVE-2023-25722Jenkins Plugin Veracode Scan 安全漏洞
CVE-2023-25721Jenkins Plugin Veracode Scan 安全漏洞
CVE-2023-25262Stimulsoft GmbH Stimulsoft Designer 代码问题漏洞
CVE-2023-25260Stimulsoft 安全漏洞
CVE-2023-24308PDF-XChange Editor 安全漏洞
CVE-2023-24304IrfanView 输入验证错误漏洞

Showing 20 of 28 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2023-1679へのコメント

まだコメントはありません


コメントを残す