CVE-2020-15368
Severity:
MEDIUM
Type:
Unavailable / Other
Publication date:
29/06/2020
Last modified:
09/07/2020
Description
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
Low
Vulnerable products and versions
- cpe:2.3:o:asrock:rgb_driver_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:h:asrock:rgb_driver:-:*:*:*:*:*:*:*
To consult the complete list of products and versions see this page
References to Advisories, Solutions, and Tools
- https://codetector.org/post/asrock_rgb_driver/ (Source:MISC)