CVE-2021-31727
HIGH 7.8EPSS 0.4%
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x80002010 and send these IOCTL's to escalate privileges by overwriting the boot sector or overwriting critical code in the pagefile.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 0.37% chance of exploitation in the next 30 days, 30th percentile
- Published
- 2021-05-17
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- irql/CVE-2021-3172889★ · 2021-05-10
- irql0/CVE-2021-3172889★ · 2021-05-10