7.8
CVSSv3

CVE-2020-11520

Published: 22/06/2020 Updated: 03/05/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and previous versions allows local users to write to arbitrary kernel memory addresses because the IOCTL dispatcher lacks pointer validation. Exploiting this vulnerability results in privileged code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

winmagic securedoc

Github Repositories

Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520

Technical Write-up on CVE-2020-11519 and CVE-2020-11520 Date: June 2020 Author: Dennis Elser (code: github) Table of Contents Introduction Approach and Technical Description CVE-2020-11519 CVE-2020-11520 Proof-of-Concept Exploit Disclosure Timeline Solution Checksums References Introduction In reference to its web representation, Winmagic SecureDoc "allows businesses