CVE-2024-12656 MEDIUM

CVE-2024-12656: FabulaTech USB over Network IOCT ftusbbus2.sys 0x220448 null pointer dereference

Vendor Fabulatech
Product USB over Network
Weakness CWE-476
Published December 16, 2024
Last update December 16, 2024

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Key dates

02Disclosure timeline

December 16, 2024 CVE published
December 16, 2024 Record updated