WinPmem Improper Input Validation vulnerability
Vulnerability Description
Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with admin access can trigger a BSOD with a parallel thread changing the memory’s access right under the control of the user-mode application. This is due to verification only being performed at the beginning of the routine allowing the userspace to change page permissions half way through the routine. A valid workaround is a rule to detect unauthorized loading of winpmem outside incident response operations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10972
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- We thank David Baptiste from the ERNW Vulnerability Disclosure Team for responsibly disclosing this issue.
Affected Vendor
Velocidex
View all reports →