See.sys, up to version 4.25, in SoftEther VPN Server versions 4.29 or older, allows a user to call an IOCTL specifying any kernel address to which arbitrary bytes are written to.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/SoftEtherVPN/SoftEtherVPN/tree/master/src/See | third party advisory |
https://downwithup.github.io/CVEPosts | third party advisory |
https://www.softether.org/9-about/News/900-SEVPN201901 | vendor advisory |