Privilege Escalation Vulnerability in NZXT CAM Software by NZXT
CVE-2020-13514

8.8HIGH

Key Information:

Vendor

Nzxt

Status
Vendor
CVE Published:
18 December 2020

What is CVE-2020-13514?

The NZXT CAM software version 4.8.0 is susceptible to a privilege escalation vulnerability due to a flaw in the WinRing0x64 Driver's handling of Privileged I/O Write IRPs. With a specially crafted I/O request packet (IRP), low privilege users can gain unrestrained access to the OUT instruction at higher privilege levels. This vulnerability allows attackers to exploit the system by sending malicious IRPs, thereby compromising user permissions and potentially leading to unauthorized access.

Affected Version(s)

NZXT NZXT CAM 4.8.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.