Vulnerabilities > CVE-2019-11490 - Double Free vulnerability in Nmap Npcap 0.992

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
nmap
CWE-415

Summary

An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel pool corruption. This could lead to arbitrary code executing inside the Windows kernel and allow escalation of privileges.

Vulnerable Configurations

Part Description Count
Application
Nmap
1

Common Weakness Enumeration (CWE)