CVE-2019-8372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
18/02/2019
Last modified:
26/02/2019

Description

The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lg:lha.sys:*:*:*:*:*:*:*:* 1.1.1811.2101 (excluding)