Denial of Service Vulnerability in shzh by Hangzhou Shunwang Technology
CVE-2026-94137

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94137?

A local denial of service vulnerability exists in Hangzhou Shunwang Technology's shzh product, specifically in version 10.7.2.693. This issue stems from improper handling of the argument PID in the subsystem IRP_MJ_DEVICE_CONTROL within the shdrv_x64.sys file. Attackers with local access can exploit this vulnerability to cause a denial of service. It's essential for organizations utilizing affected versions to apply necessary patches to mitigate this risk.

Affected Version(s)

shzh 10.7.2.693

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Element2023H (VulDB User)
.