VYPR
High severity7.8NVD Advisory· Published May 14, 2024· Updated Apr 15, 2026

CVE-2024-29513

CVE-2024-29513

Description

An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local attacker can execute arbitrary code and cause denial-of-service via insufficient DACL on the device object created by BlueRiSC's briscKernelDriver.sys in WindowsSCOPE Cyber Forensics before 3.3.

Vulnerability

Overview CVE-2024-29513 is a vulnerability in the briscKernelDriver.sys driver used by BlueRiSC WindowsSCOPE Cyber Forensics prior to version 3.3. The root cause is an improperly configured Discretionary Access Control List (DACL) on the device object \\.\BriscKernel, which grants overly permissive access to unprivileged users [1].

Exploitation

A local attacker with low privileges can open a handle to the device and send crafted IOCTL requests. This can trigger arbitrary memory operations within the driver context, leading to arbitrary code execution at kernel level. Additionally, passing incorrect data can cause a kernel bugcheck (BSOD), resulting in denial-of-service [1].

Impact

Successful exploitation allows an attacker to execute arbitrary code in kernel mode, compromising the entire system. They can also trigger a denial-of-service condition, causing system instability or crash. The vulnerability requires local access but no special privileges [1].

Mitigation

BlueRiSC released version 3.3 of WindowsSCOPE Cyber Forensics, which silently addressed this issue by correcting the DACL on the device object. Users are advised to update to version 3.3 or later. No known workarounds exist [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.