CVE-2017-15303

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
16/10/2017
Last modified:
20/04/2025

Description

In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ioctl 0x9C402430 call to the kernel-mode driver (e.g., cpuz141_x64.sys for version 1.41).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cpuid:cpu-z:*:*:*:*:*:windows:*:* 1.42 (including)