CVE-2019-9729

HIGH

Shanda MapleStory Online V160 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.

Exploits (2)

nomisec WORKING POC 83 stars
by HyperSine · poc
https://github.com/HyperSine/SdoKeyCrypt-sys-local-privilege-elevation
nomisec WRITEUP
by recozone · poc
https://github.com/recozone/HyperSine

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0242
EPSS Percentile 85.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-129 CWE-787
Status published
Products (1)
shanda/maplestory_online 160.0
Published Mar 12, 2019
Tracked Since Feb 18, 2026