Advisories

Yenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial of Service (PoC)

Go Back
severity
medium
date
Affecting
  • Yenkee Hornet Gaming Mouse all version

CWE
  • CWE-121 Stack-based Buffer Overflow
CVSS
6.8
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Credit
Quadron Research Lab
Description
Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash the system by sending oversized input. Attackers can exploit the driver by sending a 2000-byte buffer through DeviceIoControl to trigger a kernel-level system crash.