PT-2019-15779 · Kyrol · Kyrol Internet Security
Publicado
2019-11-21
·
Atualizado
2019-12-04
·
CVE-2019-19197
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kyrol Internet Security version 9.0.6.9
Description
The issue concerns the IOCTL handling in the kyrld.sys driver, allowing an attacker to achieve privilege escalation, denial-of-service, and code execution. This is possible because the IOCTL code 0x9C402401 using METHOD NEITHER results in a read primitive, which can be exploited via usermode.
Recommendations
For Kyrol Internet Security version 9.0.6.9, consider disabling the kyrld.sys driver as a temporary workaround until a patch is available. Restrict access to the IOCTL code 0x9C402401 to minimize the risk of exploitation. Avoid using the METHOD NEITHER method in the affected driver until the issue is resolved.
Exploit
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kyrol Internet Security