A vulnerability in the SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to access physical disk sectors via the \.\SecureDocDevice handle. This improper access control enables attackers to read or write arbitrary disk sectors, potentially leading to privileged code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a technical write-up and a working proof-of-concept (PoC) exploit for two local privilege escalation vulnerabilities (CVE-2020-11519 and CVE-2020-11520) in Winmagic SecureDoc for Windows (versions 8.3, 8.5, and likely earlier). The main exploit is implemented in 'sd_poc.py', a Python script that interacts directly with the vulnerable kernel driver 'SDDisk2k.sys' via the device object '\\.\SecureDocDevice'. The exploit works by opening a handle to the device, leveraging insecure IOCTL handling to locate and patch the current process token, and then spawning a SYSTEM-level command prompt. The attack is purely local and requires the attacker to have code execution on the target system. The repository also includes a detailed Readme.md with technical background, exploitation details, disclosure timeline, and references. No network endpoints are involved; the attack vector is local, targeting a device object exposed by the vulnerable driver.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.