Vulnerabilities > CVE-2020-8808 - Unspecified vulnerability in Corsair Icue 3.12.118/3.20.80/3.23.66
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, via a function call such as MmMapIoSpace.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |