CVE-2018-10711
HIGHASRock RGBLED <1.0.35.1, A-Tuning/F-Stream <3.0.210, RestartToUEFI <1.0.6.2 - Ring-0 Code Execution via MSR
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-10711. PoCs published by SecureAuth.
AI-analyzed exploit summary The provided code demonstrates multiple local privilege escalation vulnerabilities in ASRock drivers (AsrDrv101.sys and AsrDrv102.sys) by exposing IOCTL functionality for CR register access, arbitrary physical memory read/write, and MSR register access. These vulnerabilities allow non-privileged users to execute arbitrary ring-0 code and elevate privileges.
Description
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
Exploits (1)
The provided code demonstrates multiple local privilege escalation vulnerabilities in ASRock drivers (AsrDrv101.sys and AsrDrv102.sys) by exposing IOCTL functionality for CR register access, arbitrary physical memory read/write, and MSR register access. These vulnerabilities allow non-privileged users to execute arbitrary ring-0 code and elevate privileges.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H