Local Denial of Service in Jingyun Antivirus Driver Vulnerability
CVE-2018-16721

7.8HIGH

Key Information:

Vendor

V-secure

Vendor
CVE Published:
23 November 2020

What is CVE-2018-16721?

Jingyun Antivirus version 2.4.2.39 contains a vulnerability in the ZySandbox.sys driver that allows local users to exploit this flaw by sending unvalidated input values via the IOCtl 0x12360090 command. This can lead to a denial of service (BSOD) scenario, potentially resulting in system instability or further unspecified impacts on the affected system. It is crucial for users to update their software to mitigate possible risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.