CVE-2008-7211 describes a local privilege escalation vulnerability in the CreativeLabs es1371mp.sys WDM audio driver (version 5.1.3612.0), affecting Ensoniq PCI 1371 sound cards on Windows Vista. The driver fails to properly create a Functional Device Object (FDO), allowing user-mode access to the Physical Device Object (PDO). This flaw enables a local attacker to gain SYSTEM privileges by sending a crafted IRP request that dereferences a NULL FsContext pointer. With a CVSS score of 6.9, this vulnerability is considered high severity due to its potential for complete compromise of confidentiality, integrity, and availability (C:C/I:C/A:C). While it requires local access and medium attack complexity (AV:L/AC:M), the impact is significant. Although not listed on CISA's KEV catalog, an exploit for this vulnerability (EDB-30999) is publicly available on ExploitDB. There is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1.3612.0CPE matchmatch criteria | cpe:2.3:h:soundblaster:ensoniq_pci_es1371_wdm_driver:5.1.3612.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.