Denial of Service Vulnerability in Jingyun Antivirus by Jingyun Technology
CVE-2018-16720

7.8HIGH

Key Information:

Vendor

V-secure

Vendor
CVE Published:
23 November 2020

What is CVE-2018-16720?

In Jingyun Antivirus version 2.4.2.39, the driver file ZySandbox.sys is susceptible to exploitation due to improper input validation from the IOCtl command 0x1236001c. This vulnerability can be leveraged by local users to trigger a denial of service, potentially resulting in system crashes or other undefined impacts. Such flaws underscore the critical need for robust input validation mechanisms to safeguard against local threats.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.