CVE-2024-36054

HIGH

Marvin Test HW.exe <5.0.5.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via MmMapIoSpace) and IOCTL 0x9c406490 (via ZwMapViewOfSection).

Scores

CVSS v3 7.4
EPSS 0.0006
EPSS Percentile 19.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-125
Status published
Published May 26, 2024
Tracked Since Feb 18, 2026