CVE Feed

    Dashboard / CVE / CVE-2019-18845

    CVE-2019-18845

    The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.

    Published:Nov 9, 2019
    Last Modified:Nov 21, 2024
    EPS:Nov 9, 2019
    EPSS Score:0.00087
    CVSS Score:7.1

    Affected Products

    Vendor
    Patriotmemory
    Product
    Viper Rgb
    Vendor
    Patriotmemory
    Product
    Viper Rgb Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High