CVE-2024-55412 Details
Description
A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
A vulnerability in the SUNIX Serial Driver x64 version 10.1.0.0 has been identified in the driver file snxpsamd.sys. This vulnerability allows low-privileged users to read and write to arbitrary I/O ports by sending specially crafted IOCTL requests. The issue can be exploited for privilege escalation, enabling code execution with elevated rights, and unauthorized information disclosure. Additionally, these signed drivers could potentially circumvent the Microsoft driver-signing policy to execute malicious code.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 7, 2025CISA-ADP
Assessed Jan 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55412/CVE-2024-55412_snxpsamd.sys_README.md | [email protected] | ExploitTechnical Description |
| https://www.sunix.com/tw/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SUNIX Serial Driver x64 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2025 | CVE Modified | CISA-ADP |
| Jan 7, 2025 | New CVE Received | [email protected] |
Volerion