CVE-2021-47789

HIGH

Yenkee YMS 3029 Firmware - Denial of Service via GM312Fltr.sys DeviceIoControl Buffer Overrun

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47789. PoCs published by Quadron Research Lab.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in the Yenkee Hornet Gaming Mouse driver (GM312Fltr.sys) by sending a malformed IOCTL request with a large buffer, causing a stack-based buffer overflow and triggering a BSOD (Bugcheck 0xF7). The PoC is functional and includes a crash analysis.

Description

Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash the system by sending oversized input. Attackers can exploit the driver by sending a 2000-byte buffer through DeviceIoControl to trigger a kernel-level system crash.

Exploits (1)

exploitdb WORKING POC
by Quadron Research Lab · pythondoswindows
https://www.exploit-db.com/exploits/50311

This exploit demonstrates a denial-of-service (DoS) vulnerability in the Yenkee Hornet Gaming Mouse driver (GM312Fltr.sys) by sending a malformed IOCTL request with a large buffer, causing a stack-based buffer overflow and triggering a BSOD (Bugcheck 0xF7). The PoC is functional and includes a crash analysis.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Yenkee Hornet Gaming Mouse GM312Fltr.sys (all versions)
No auth needed
Prerequisites: Access to a system with the vulnerable driver installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-121 CWE-787
Status published
Products (2)
Yenkee/Yenkee Hornet Gaming Mouse all version
yenkee/yms_3029_firmware
Published Jan 16, 2026
Tracked Since Feb 18, 2026