CVE-2017-15920
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002054. This is due to the input buffer being NULL or the input buffer size being 0 as they are not validated.
Affected (2)
Products: Watchdogdevelopment: Anti Malware, Online Security Pro
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.74.186.150 | |
| Version 2.74.186.150 |
Related CWEs
References (4)
Source: cve@mitre.org
ExploitIssue TrackingThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitIssue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party AdvisoryVDB Entry
Timeline
No history available yet.