PT-2021-9440 · Max Secure · Max Secure Max Spyware Detector

Published

2021-02-05

·

Updated

2021-07-21

·

CVE-2020-12122

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Max Secure Max Spyware Detector version 1.0.0.044
Description The issue allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x2200019 in the driver file MaxProc64.sys. This also extends to the various other products from Max Secure that include MaxProc64.sys.
Recommendations For Max Secure Max Spyware Detector version 1.0.0.044, consider disabling the MaxProc64.sys driver file as a temporary workaround until a patch is available. Restrict access to the IOCtl 0x2200019 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12122

Affected Products

Max Secure Max Spyware Detector