CVE-2017-14961
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.5%
from disclosure to weapon0 days
Published on NVDNov 15
1st PoCNov 13
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/144955/IKARUS-AntiVirus-2.16.7-Privilege-Escalation.htmlunverifiedcve_referencewww.exploit-db.com/exploits/43139/unverifiedexploitdbwww.exploit-db.com/exploits/43139unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/144955/IKARUS-AntiVirus-2.16.7-Privilege-Escalation.htmlhttps://theevilbit.blogspot.co.uk/2017/11/turning-cve-2017-14961-ikarus-antivirus.htmlhttps://www.exploit-db.com/exploits/43139/https://www.ikarussecurity.com/about-ikarus/security-blog/vulnerability-in-windows-antivirus-products-ik-sa-2017-0002/