In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x1236001c, a related issue to CVE-2018-16304.
References
Link | Resource |
---|---|
https://github.com/bsauce/poc/tree/master/jingyun_antivirus_1236001c | Third Party Advisory |
https://www.cnvd.org.cn/flaw/show/CNVD-2018-19267 | Third Party Advisory |
Configurations
Information
Published : 2020-11-23 13:15
Updated : 2020-11-25 06:49
NVD link : CVE-2018-16720
Mitre link : CVE-2018-16720
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
v-secure
- jingyun_antivirus