Access of Uninitialized Pointer in APM Clients and BIG-IP APM - CVE-2020-5898
Published: May 13, 2020
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to the BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user can send specially crafted DeviceIoControl requests to a \\.\urvpndrv device and crash the Windows kernel.
Affected software
BIG-IP APM