CVE-2023-38817

HIGH EXPLOITED

Inspect Element Ltd Echo.ac <5.2.1.0 - Privilege Escalation

Title source: llm

Description

An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself."

Exploits (2)

nomisec WORKING POC 18 stars
by vxcall · poc
https://github.com/vxcall/kur
nomisec WORKING POC
by SecSecBurger · local
https://github.com/SecSecBurger/CVE-2023-38817

Scores

CVSS v3 7.8
EPSS 0.0080
EPSS Percentile 74.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-09-10
CWE
CWE-269
Status published
Products (1)
echo/anti_cheat_tool < 5.2.1.0
Published Oct 11, 2023
Tracked Since Feb 18, 2026