Privilege Escalation Vulnerability in Insyde Software SEG Windows Driver
CVE-2024-33228

8.4HIGH

Key Information:

Vendor
CVE Published:
22 May 2024

What is CVE-2024-33228?

A vulnerability exists in the segwindrvx64.sys component of Insyde Software Corp's SEG Windows Driver version 100.00.07.02. This flaw enables attackers to escalate their privileges and execute arbitrary code by sending specially crafted IOCTL requests. This malicious exploitation could lead to significant security breaches, putting systems at risk. Organizations using the affected driver version should take immediate measures to assess their systems and apply relevant security patches.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.