7.8

CVE-2015-5466

Exploit
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SisXgi Vga Display Manager Version6.14.10.1090
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.13% 0.622
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

http://packetstormsecurity.com/files/133400/XGI-Windows-VGA-Display-Manager-Privilege-Escalation.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2015/Sep/2
Third Party Advisory
Exploit
Mailing List
http://www.securityfocus.com/archive/1/archive/1/536373/100/0/threaded
Broken Link
https://www.korelogic.com/Resources/Advisories/KL-001-2015-004.txt
Third Party Advisory
Exploit