CVE-2024-55412 – SUNIX Serial Driver x64_PRIVILEGE ESCALATION

The following table lists the changes that have been made to the
CVE-2024-55412 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 07, 2025

    Action Type Old Value New Value
    Added Description A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 – 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
    Added Reference https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55412/CVE-2024-55412_snxpsamd.sys_README.md
    Added Reference https://www.sunix.com/tw/
Share the Post:

Related Posts