Home

Description

Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash the system by sending oversized input. Attackers can exploit the driver by sending a 2000-byte buffer through DeviceIoControl to trigger a kernel-level system crash.

PUBLISHED Reserved 2026-01-14 | Published 2026-01-15 | Updated 2026-01-16 | Assigner VulnCheck




MEDIUM: 6.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Stack-based Buffer Overflow

Product status

all version
affected

Credits

Quadron Research Lab finder

References

www.exploit-db.com/exploits/50311 exploit

www.exploit-db.com/exploits/50311 (ExploitDB-50311) exploit

www.yenkee.eu/ (Yenkee Vendor Webpage) product

github.com/...rch-Lab/Kernel_Driver_bugs/tree/main/GM312Fltr (Quadron Research Lab Kernel Driver Bugs Repository) technical-description exploit

www.vulncheck.com/...g-mouse-gmfltrsys-denial-of-service-poc (VulnCheck Advisory: Yenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial of Service (PoC)) third-party-advisory

cve.org (CVE-2021-47789)

nvd.nist.gov (CVE-2021-47789)

Download JSON