CVE-2025-63602

Source
https://cve.org/CVERecord?id=CVE-2025-63602
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63602.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-63602
Published
2025-11-18T16:15:45.593Z
Modified
2026-03-13T03:40:50.739465Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to IntelliBreeze.Maintenance.Service.sys) that lacks a properly secured DACL, allowing unprivileged users to interact with the driver and, as a result, the kernel. This can result in local privilege escalation, information disclosure, denial of service, and other unspecified impacts.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63602.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "11.2.4"
            }
        ]
    }
]