CVE-2024-34332: Sisoftware Sandra

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent to the Kernel Driver using the DeviceIoControl Windows API.

Affected products

  • Sisoftware Sandra: before v31.66 (fixed in v31.66)

Published 2024-06-10. Last modified 2026-06-17.