Denial of Service Vulnerability in Jingyun Antivirus by Jingyun
CVE-2018-16723

7.8HIGH

Key Information:

Vendor

V-secure

Vendor
CVE Published:
23 November 2020

What is CVE-2018-16723?

In Jingyun Antivirus version 2.4.2.39, a vulnerability exists in the driver file ZySandbox.sys that can be exploited by local users. The flaw arises from the lack of input validation when handling specific IOCTL (Input Output Control) requests, allowing attackers to potentially trigger a denial of service (BSOD). This absence of validation creates an opportunity for unspecified impacts, which may further compromise system stability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.