JiangMin Antivirus IOCTL kvcore.sys 0x222010 memory corruption
CVE-2023-1629

7.8HIGH

Key Information:

Vendor

JiangMin

Status
Vendor
CVE Published:
25 March 2023

What is CVE-2023-1629?

A local memory corruption vulnerability exists in JiangMin Antivirus, specifically within the 0x222010 function of the kvcore.sys library associated with the IOCTL Handler. This flaw allows malicious actors to manipulate memory, posing a significant risk to system integrity. Given that this vulnerability has been publicly disclosed, prompt investigation and remediation are advised to safeguard against potential exploitation.

Affected Version(s)

Antivirus 16.2.2022.418

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zeze7w (VulDB User)
.