CVE-2010-1592 describes a privilege escalation or denial-of-service vulnerability in the sandra.sys device driver within SiSoftware Sandra versions 16.10.2010.1 and earlier. This local vulnerability, with a CVSS score of 6.9, allows an attacker to gain full control of the system or cause a system crash through unspecified vectors related to Model-Specific Registers. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. However, it has garnered some community discussion and media coverage, suggesting awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 16.10.2010.1CPE matchmatch criteria | cpe:2.3:a:sisoftware:sandra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.