Improper Privilege Management in NZXT CAM - CVE-2020-13511
Published: December 17, 2020
NZXT CAM
NZXT
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to improper privilege management in the WinRing0x64 Driver Privileged I/O Read IRPs functionality. A local user can send a specially crafted 0x9c4060d4 I/O request packet (IRP) and gain unauthorized access to sensitive information on the system.
Note: This IRP reads four bytes (one dword).