In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to increase user privileges.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.drivergenius.com/ | product |
https://github.com/y5s5k5/POCtemp8 | third party advisory broken link |
https://github.com/y5s5k5/CVE-2020-23740 | third party advisory broken link |
https://www.cnvd.org.cn/flaw/show/2438470 | third party advisory |