PT-2024-16664 · Unknown · Twister Antivirus
Andres Roldan
·
Published
2024-02-13
·
Updated
2024-12-03
·
CVE-2024-1096
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Twister Antivirus version 8.17
Description
The issue allows Elevation of Privileges on the computer where Twister Antivirus is installed by triggering specific IOCTL codes of the fildds.sys driver, including 0x80112067, 0x801120CB, and 0x801120CC. This can be exploited to gain elevated privileges.
Recommendations
For Twister Antivirus version 8.17, consider disabling the fildds.sys driver or restricting access to the vulnerable IOCTL codes as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Twister Antivirus