Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2015-2291

Description

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

POC

Reference

- http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html

- https://www.exploit-db.com/exploits/36392/

Github

- https://github.com/474172261/KDU

- https://github.com/ARPSyndicate/cvemon

- https://github.com/BlackTom900131/awesome-game-security

- https://github.com/Exploitables/CVE-2015-2291

- https://github.com/Ostorlab/KEV

- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors

- https://github.com/RivaTesu/iHaek

- https://github.com/Tare05/Intel-CVE-2015-2291

- https://github.com/gmh5225/CVE-2015-2291

- https://github.com/gmh5225/awesome-game-security

- https://github.com/h4rmy/KDU

- https://github.com/hfiref0x/KDU

- https://github.com/nanaroam/kaditaroam

- https://github.com/robertfischman/game-security

- https://github.com/sl4v3k/KDU

- https://github.com/trevor0106/game-security

- https://github.com/vitorallo/BYOVD