PT-2019-15971 · Kyrol · Kyrol Internet Security
Published
2019-12-16
·
Updated
2020-01-22
·
CVE-2019-19820
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kyrol Internet Security version 9.0.6.9
Description
The issue is related to an invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver. This vulnerability allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode. The vulnerability is triggered by using the
0x9C402405 IOCTL code with the METHOD NEITHER method, resulting in a read primitive.Recommendations
For Kyrol Internet Security version 9.0.6.9, consider disabling the kyrld.sys driver as a temporary workaround until a patch is available. Restrict access to the IOCTL Handling functionality to minimize the risk of exploitation. Avoid using the
0x9C402405 IOCTL code with the METHOD NEITHER method in the affected driver until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyrol Internet Security