« Volver al listado

CVE-2023-44976

Estado: AplazadaBaja (3.2)—

Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as exploited in the wild in October 2023.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-44976",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-44976",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-01T14:27:49.967204Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 3.2,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "Hangzhou Shunwang",
          "product": "Rentdrv2",
          "versions": [
            {
              "status": "affected",
              "version": "1aed62a63b4802e599bbd33162319129501d603cceeb5e1eb22fd4733b3018a3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a5",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-08-01T14:15:34.350",
  "references": [
    {
      "url": "https://github.com/keowu/BadRentdrv2",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-782"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as exploited in the wild in October 2023."
    },
    {
      "lang": "es",
      "value": "Hangzhou Shunwang Rentdrv2 anterior al 24/12/2024 permite a los usuarios locales finalizar procesos EDR y posiblemente tener otro impacto no especificado a través de DeviceIoControl con el código de control 0x22E010, como se explotó en la naturaleza en octubre de 2023."
    }
  ],
  "lastModified": "2026-06-17T06:28:00.980",
  "sourceIdentifier": "cve@mitre.org"
}