Motorola SM56 Modem WDM Driver Privilege Escalation Vulnerability

Vulnerability

A vulnerability in the Motorola SM56 Modem WDM Driver, specifically in the SmSerl64.sys file, version 6.12.23.0, allows low-privileged users to map physical memory through specially crafted IOCTL requests. This vulnerability can be exploited for privilege escalation, leading to code execution with elevated rights and unauthorized information disclosure. Additionally, these signed drivers could potentially bypass the Microsoft driver-signing policy to execute malicious code.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation, allowing low-privileged users to execute code with high privileges and access sensitive information.

Reproduction

The vulnerability can be reproduced by sending IOCTL requests to the affected driver. IOCTL codes 0x1B2890 and 0x1B2880 trigger the memory mapping operation, which can be exploited to access physical memory.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.