← back
CVE-2023-1628

Jianming Antivirus IoControlCode kvcore.sys null pointer dereference

CVSS 5.5 MEDIUMEPSS 0.3%CWE-476
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability classified as problematic has been found in Jianming Antivirus 16.2.2022.418. Affected is an unknown function in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. VDB-224010 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
Jianming · Antivirus

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →