Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x80002010 and send these IOCTL's to escalate privileges by overwriting the boot sector or overwriting critical code in the pagefile.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-05-17T12:05:50
Updated: 2024-08-03T23:03:33.703Z
Reserved: 2021-04-23T00:00:00
Link: CVE-2021-31727
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-05-17T13:15:07.773
Modified: 2024-11-21T06:06:09.477
Link: CVE-2021-31727
Redhat
No data.