Security Advisory

CVE-2016-9038

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-04-24 19:00:00
Last updated 2024-09-17 00:26:38
Assigner talos
CVSS score 7.8
State PUBLISHED

Description

An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result in kernel memory corruption, which could result in privilege escalation. An attacker needs to execute a special application locally to trigger this vulnerability.