CVE-2023-38817

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
11/10/2023
Last modified:
02/08/2024

Description

An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:echo:anti_cheat_tool:*:*:*:*:*:*:*:* 5.2.1.0 (excluding)


References to Advisories, Solutions, and Tools