CVE-2019-8372 describes a privilege escalation vulnerability in the LHA.sys driver of LG Device Manager, affecting versions before 1.1.1811.2101. This flaw allows low-privileged users to read and write arbitrary physical memory by sending specially crafted IOCTL requests, due to an open DACL on the device object's symbolic link. Rated 7.0 HIGH, the attack requires local access but has high impact on confidentiality, integrity, and availability, with high attack complexity. There is no evidence of active exploitation, nor are there public exploit modules in Metasploit or ExploitDB, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.1811.2101CPE matchmatch criteria | cpe:2.3:a:lg:lha.sys:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.