Impact
The vulnerability in the URDSCSI.sys kernel driver of ieungSoft Ultra RAMDisk Pro allows a local attacker to manipulate privilege handling. By exploiting improper privilege management, a user can elevate privileges beyond their intended scope. This flaw can lead to a privilege escalation that permits full system control, and a publicly disclosed exploit demonstrates its feasibility.
Affected Systems
The affected product is ieungSoft Ultra RAMDisk Pro version 1.82, specifically its Kernel Driver component URDSCSI.sys, which lies within the library used by the application.
Risk and Exploitability
The CVSS score of 9.3 highlights a high severity vulnerability with a local attack vector and no network exploitation required. While the EPSS score is not available, the public disclosure of an exploit indicates a potentially high exploitation probability. The vulnerability is not listed in the CISA KEV catalog, yet the impact remains critical for any system running the vulnerable driver.
OpenCVE Enrichment