CVE-2019-7245
An issue was discovered in GPU-Z.sys in TechPowerUp GPU-Z before 2.23.0. The vulnerable driver exposes a wrmsr instruction via an IOCTL and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
- Affected products
- Gpu-Z
- Techpowerup Gpu-z
- < 2.23.0
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 2.4% (83th percentile)
- Weakness
- CWE-665
- NVD status
- Modified
- Published
- 2020-03-25
CVE-2019-7245 at NVD
1 known exploit for CVE-2019-7245
Proof-of-concept code and exploit modules indexed by Sploitus