Access of Uninitialized Pointer in BIG-IP APM and APM Clients - CVE-2020-5898
Published: May 13, 2020
BIG-IP APM
APM Clients
F5 Networks
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to the BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user can send specially crafted DeviceIoControl requests to a \\.\urvpndrv device and crash the Windows kernel.