4.6
CVSSv2

CVE-2017-6178

Published: 20/03/2017 Updated: 13/03/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

usbpcap project usbpcap 1.1.0.0

Exploits

/* Exploit Title - USBPcap Null Pointer Dereference Privilege Escalation Date - 07th March 2017 Discovered by - Parvez Anwar (@parvezghh) Vendor Homepage - desowinorg/usbpcap/ Tested Version - 1100 (USB Packet capture for Windows bundled with WireShark 225) Driver Version - 1100 - USBPcapsys Tested on OS ...
USBPcap version 1100 suffers from a privilege escalation vulnerability ...