Out of Bounds Write Vulnerability in Velocidex WinPmem
CVE-2024-12668
8.2HIGH
What is CVE-2024-12668?
CVE-2024-12668 is a critical Out of Bounds Write vulnerability in Velocidex WinPmem versions prior to 4.1. This flaw enables attackers to compromise code-signing mechanisms, leading to a potential scenario where the attacker can manipulate memory by writing the value zero to arbitrary locations. This vulnerability poses a significant risk as it allows for unauthorized memory manipulation without the requirement of the PMEM_WRITE_ENABLED compilation flag. Users of affected versions are strongly urged to upgrade to WinPmem version 4.1 or later to mitigate this security threat.
Affected Version(s)
WinPmem < 4.1
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We thank David Baptiste from the ERNW Vulnerability Disclosure Team for responsibly disclosing this issue.