Advantech SUSI Driver Improper Access Control Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution
Vulnerability
A vulnerability in the Advantech SUSI driver (susi.sys) related to improper access control has been identified. This vulnerability allows attackers to read and write arbitrary memory, I/O ports, and Model Specific Registers (MSRs). The consequences of this vulnerability include privilege escalation, arbitrary code execution, and unauthorized information disclosure. It affects Advantech SUSI versions 5.0.24335 and prior.
Impact
Exploitation of this vulnerability could lead to unauthorized access to privileged resources, allowing for elevated rights and the execution of arbitrary code within the affected system.
Remediation
Users can upgrade to Advantech SUSI version 5.0.24336 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
