Researcher finds new vulnerable AIDA64 driver builds
A researcher identified additional signed AIDA64 driver builds (aida64x.sys and aida64.sys) vulnerable to CVE-2024-26507, a local privilege escalation via arbitrary physical memory read/write. The flaw affects current AIDA64 8.x packages, and the findings were added to the existing NVD record.
- CVE-2024-26507: local privilege escalation, CVSS 7.8 (High)
- Driver creates \Device\AIDA64Driver with no ACL, open to any process
- IOCTLs allow physical memory read/write with no validation
- Additional builds vulnerable, including AIDA64 8.x packages
Read next
Security