Access Control Vulnerability in Jiangmin Antivirus 21
CVE-2026-19193
Key Information:
Badges
What is CVE-2026-19193?
A vulnerability has been identified in Jiangmin Antivirus 21 that affects the MessageNotifyCallback function within the kvcore.sys library of the Minifilter Port. This flaw allows for improper access controls, enabling local attackers to potentially exploit the system through unauthorized manipulation. The exploit has been made public, indicating a pressing security risk to users of this antivirus product. Despite early disclosures to the vendor, a response was not received, raising concerns about the remediation of this issue.
Affected Version(s)
Antivirus 21
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
