← back
CVE-2023-1629

JiangMin Antivirus IOCTL kvcore.sys 0x222010 memory corruption

CVSS 5.3 MEDIUMEPSS 0.4%CWE-119
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability classified as critical was found in JiangMin Antivirus 16.2.2022.418. Affected by this vulnerability is the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224011.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
JiangMin · Antivirus

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →