CVE-2023-31096
EUVD-2023-3542510.10.2023, 19:15
An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege Escalation to SYSTEM via a Stack Overflow in RTLCopyMemory (IOCTL 0x1b2150). An attacker can exploit this to elevate privileges from a medium-integrity process to SYSTEM. This can also be used to bypass kernel-level protections such as AV or PPL, because exploit code runs with high-integrity privileges and can be used in coordinated BYOVD (bring your own vulnerable driver) ransomware campaigns.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| broadcom | lsi_pci-sv92ex_firmware | 𝑥 ≤ 2.2.100.1 |
𝑥
= Vulnerable software versions
Windows Releases
Platform | Version | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Windows 10 |
| ||||||||
| Windows 11 |
| ||||||||
| Windows Server 2008 |
| ||||||||
| Windows Server 2008 R2 |
| ||||||||
| Windows Server 2012 |
| ||||||||
| Windows Server 2012 R2 |
| ||||||||
| Windows Server 2016 |
| ||||||||
| Windows Server 2019 |
| ||||||||
| Windows Server 2022 |
| ||||||||
| Windows Server 2025 |
|
Common Weakness Enumeration
Vulnerability Media Exposure