Local Denial of Service in Jiangmin Antivirus Driver File
CVE-2018-6781

7.8HIGH

Key Information:

Vendor

Jiangmin

Status
Vendor
CVE Published:
3 October 2022

What is CVE-2018-6781?

In Jiangmin Antivirus version 16.0.0.100, a vulnerability in the driver file KSysCall.sys exposes the system to local denial of service attacks. The issue arises from improper validation of input values sent through IOCtl 0x9A008264, potentially leading to a Blue Screen of Death (BSOD) or other unspecified adverse effects. Local users could exploit this weakness to disrupt service availability, emphasizing the importance of prompt security measures.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.