CVE-2019-11490

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
24/04/2019
Last modified:
29/04/2019

Description

An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel pool corruption. This could lead to arbitrary code executing inside the Windows kernel and allow escalation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nmap:npcap:0.992:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools