Impact
The vulnerability involves a stack-based buffer overflow in the ETDSMBus.sys driver on Windows. During Intel SMBus recovery, the driver fails to enforce an upper‑bound check on a hardware‑derived report count, which is later used as a loop counter in ETD.sys for a stack buffer copy. When the count exceeds the buffer size, the kernel triggers a debugger stop (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in a local denial‑of‑service crash. The flaw requires an attacker to be able to trigger SMBus recovery and run with standard user privileges, making it a local privilege input that can bring the system down.
Affected Systems
The issue affects ELAN Smart‑Pad devices that run the ETD driver on Windows operating systems. Versions of the driver up to ETD24.21.52.3 are vulnerable. The bug is triggered when the driver processes Intel SMBus recovery events, so any system with the ELAN Smart‑Pad hardware and an outdated driver is impacted.
Risk and Exploitability
The CVSS score of 5.6 places the flaw in the medium severity range, and the EPSS score is not available, so exploitation likelihood is unclear. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs local access with standard user rights to trigger the overflow during SMBus recovery, so the attack vector is local. Because the flaw leads only to a denial‑of‑service crash and not remote code execution, the immediate risk to confidentiality or integrity is low, but any system that suffers a sudden crash can suffer data loss or operational disruption.
OpenCVE Enrichment