CVE-2024-55414Command Injection in Windows 10 Version 1607

Severity
9.8CRITICALNVD
EPSS
0.1%
top 74.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7
Latest updateJan 13

Description

A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages15 packages

🔴Vulnerability Details

1
GHSA
GHSA-6prq-q63r-xqhp: A vulnerability exits in driver SmSerl642025-01-07

📋Vendor Advisories

1
Microsoft
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability2026-01-13

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws2026-01-13