CVE-2023-52271 describes a vulnerability in the wsftprm.sys kernel driver (version 2.0.0.0) within Topaz Antifraud, allowing low-privileged attackers to terminate any Protected Process Light (PPL) process. This local attack has low complexity and no user interaction, leading to high availability impact (denial of service). While no public exploits or active exploitation have been observed, and media coverage is absent, there is some community discussion regarding the potential for using vulnerable drivers to disable security software.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0.0CPE matchmatch criteria | cpe:2.3:a:topazevolution:antifraud:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.