Impact
A Classic Buffer Overflow exists in the RtlQueryRegistryValues function of the Virtual Machine Driver Pack, where a buffer copy is performed without checking the input size; if an attacker can modify the registry, he can affect the integrity of the driver, though no feasible exploitation path is currently known.
Affected Systems
The vulnerability affects SUSE Virtual Machine Driver Pack versions prior to commit e7a602ec232756ead019bdf19d6d3b9d010cc94b.
Risk and Exploitability
With a CVSS score of 2 and an EPSS below 1%, the risk is low and the likelihood of exploitation is minimal; the vulnerability is not listed in the CISA KEV catalog and requires the attacker to have permission to modify registry keys, typically a local privilege escalation scenario.
OpenCVE Enrichment