CVE-2019-11868 Information
Feb 14, 2021
cve
Description
See.sys up to version 4.25 in SoftEther VPN Server versions 4.29 or older allows a user to call an IOCTL specifying any kernel address to which arbitrary bytes are written to.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://downwithup.github.io/CVEPosts https://github.com/SoftEtherVPN/SoftEtherVPN/tree/master/src/See https://www.softether.org/9-about/News/900-SEVPN201901
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: