CVE-2018-10739
Description
An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe allows local users to bypass intended process protections, and consequently terminate process, because WM_SYSCOMMAND is not properly considered.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Shanghai 2345 Security Guard 3.7.0 allows local users to bypass protected process termination via WM_SYSCOMMAND message handling.
Vulnerability
An issue exists in Shanghai 2345 Security Guard version 3.7.0. The component 2345MPCSafe.exe does not properly handle the WM_SYSCOMMAND window message. This oversight allows a local attacker to send crafted WM_SYSCOMMAND messages to the target process, bypassing the intended protection mechanisms that should prevent unauthorized termination of the security software's processes [1].
Exploitation
An attacker must have local access to the system. The exploit involves sending a WM_SYSCOMMAND message with the SC_CLOSE command to the window handle of the protected process. No additional authentication or user interaction beyond local access is required [1].
Impact
By exploiting this vulnerability, a local attacker can terminate the protected process (2345MPCSafe.exe), effectively disabling the protection offered by the 2345 Security Guard. This could lead to a denial of service condition, as the security software's process is forcefully closed. The attacker gains the ability to bypass the software's process protection [1].
Mitigation
The vendor, Shanghai 2345, has not released a public patch or fixed version for this vulnerability as of the publication date (2018-05-04). No workaround is provided in the available references. Users are advised to consider alternative security software until an update is available [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: =3.7.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
News mentions
0No linked articles in our index yet.