Urgent.News

What's breaking now, across thousands of outlets.

Tech

Finding new drivers vulnerable to CVE-2024-26507

Disclaimer I disclosed all of this publicly: the tooling, the proof of concept, and the reports. The NVD entry for CVE-2024-26507 now lists this repository ( PaulDotSH/vuln-driver-aida64 ) among its references. Some of the code and text was AI-assisted. I verified every finding, hash, IOCTL, and code path on a real Windows machine. I did not report the original CVE. Another researcher found the…

FinalWire's AIDA64 kernel driver, kerneld.x64, contains a vulnerability that allows attackers to perform local privilege escalation via arbitrary physical memory R/W. This weakness, classified as CWE-1286, has been assigned the CVE-2024-26507 identifier. The driver creates a device object, \Device\AIDA64Driver, without any access control lists (ACLs), enabling any process to open and interact with it.

The driver exposes IOCTLs that allow unprivileged callers to read and write arbitrary physical memory addresses, effectively granting them the ability to read and modify system memory. This vulnerability exists across multiple signed builds and versions of the AIDA64 utility, including recent 8.x releases, which were not previously listed in the vulnerable record.

The proof-of-concept (PoC) code demonstrates the exploitation process, involving opening the device, allocating and locking memory, scanning physical memory to locate a marker, and confirming the read and write capabilities. By utilizing this vulnerability, an attacker can gain NT AUTHORITY\SYSTEM privileges without resorting to a memory-safety bug, thus bypassing the usual security measures.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Saturday 10 October →