PT-2017-14284 · Unknown · Watchdog Anti-Malware+1

Parvez Anwar

+1

·

Published

2017-10-30

·

Updated

2017-11-18

·

CVE-2017-15920

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Watchdog Anti-Malware version 2.74.186.150 Online Security Pro version 2.74.186.150
Description The issue arises from a NULL pointer dereference vulnerability in the zam32.sys driver. This vulnerability is triggered when an operation is sent to the ioctl 0x80002054, due to the lack of validation for the input buffer and its size, which can be NULL or 0.
Recommendations For Watchdog Anti-Malware version 2.74.186.150, consider disabling the zam32.sys driver until a patch is available. For Online Security Pro version 2.74.186.150, consider disabling the zam32.sys driver until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15920

Affected Products

Online Security Pro
Watchdog Anti-Malware