CVE-2021-47789
HIGHYenkee YMS 3029 Firmware - Denial of Service via GM312Fltr.sys DeviceIoControl Buffer Overrun
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47789. PoCs published by Quadron Research Lab.
AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in the Yenkee Hornet Gaming Mouse driver (GM312Fltr.sys) by sending a malformed IOCTL request with a large buffer, causing a stack-based buffer overflow and triggering a BSOD (Bugcheck 0xF7). The PoC is functional and includes a crash analysis.
Description
Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash the system by sending oversized input. Attackers can exploit the driver by sending a 2000-byte buffer through DeviceIoControl to trigger a kernel-level system crash.
Exploits (1)
This exploit demonstrates a denial-of-service (DoS) vulnerability in the Yenkee Hornet Gaming Mouse driver (GM312Fltr.sys) by sending a malformed IOCTL request with a large buffer, causing a stack-based buffer overflow and triggering a BSOD (Bugcheck 0xF7). The PoC is functional and includes a crash analysis.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H