Executive brief
A security vulnerability exists in the Ludashi system utility driver, which is used for hardware monitoring and performance optimization. An unprivileged user on the system can exploit this flaw to read sensitive information directly from the computer's physical memory. This could allow an attacker to steal security tokens, access protected system data, and potentially gain full administrative control over the device.
Technical details
A local information disclosure vulnerability exists in the Ludashi driver (ComputerZ_x64.sys) before version 5.1025. The driver's IOCTL handler (specifically code 0xF1002508) lacks proper access control and validation of user-provided memory addresses. By passing attacker-controlled structures containing physical addresses within the lower 4GB range, an unprivileged user can trigger the MmMapIoSpace function. The driver then maps the requested physical memory and copies its contents back to user space. This allows for the leakage of sensitive kernel data structures, pointers, and security tokens, which can be used to bypass KASLR and facilitate local privilege escalation (LPE).
Affected products
- Ludashi Ludashi Driver before 5.1025
Timeline
- 2025-12-02: disclosed: Vulnerability discovered by ZhouRui
- 2026-01-15: advisory: NVD publication date