CVE-2024-55413 – SUNIX Parallel Driver x64 uninitialized IOCTL Request Vulnerability (Privilege Escalation, Code Execution, Information Disclosure)

CVE ID : CVE-2024-55413

Published : Jan. 7, 2025, 6:15 p.m. | 1 hour, 30 minutes ago

Description : A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 – 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Go to Source