Vulnerabilities > CVE-2017-6178 - NULL Pointer Dereference vulnerability in Usbpcap Project Usbpcap 1.1.0.0

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
usbpcap-project
CWE-476
exploit available

Summary

The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.

Vulnerable Configurations

Part Description Count
Application
Usbpcap_Project
1

Common Weakness Enumeration (CWE)

Exploit-Db

fileexploits/windows/local/41542.c
idEDB-ID:41542
last seen2018-11-30
modified2017-03-07
platformwindows
port
published2017-03-07
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/41542
titleUSBPcap 1.1.0.0 (WireShark 2.2.5) - Local Privilege Escalation
typelocal

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/141526/usbpcap-escalate.txt
idPACKETSTORM:141526
last seen2017-03-09
published2017-03-09
reporterParvez Anwar
sourcehttps://packetstormsecurity.com/files/141526/USBPcap-1.1.0.0-Privilege-Escalation.html
titleUSBPcap 1.1.0.0 Privilege Escalation