VYPR
Unrated severityNVD Advisory· Published May 4, 2018· Updated Sep 16, 2024

CVE-2018-10739

CVE-2018-10739

Description

An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe allows local users to bypass intended process protections, and consequently terminate process, because WM_SYSCOMMAND is not properly considered.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Shanghai 2345 Security Guard 3.7.0 allows local users to bypass protected process termination via WM_SYSCOMMAND message handling.

Vulnerability

An issue exists in Shanghai 2345 Security Guard version 3.7.0. The component 2345MPCSafe.exe does not properly handle the WM_SYSCOMMAND window message. This oversight allows a local attacker to send crafted WM_SYSCOMMAND messages to the target process, bypassing the intended protection mechanisms that should prevent unauthorized termination of the security software's processes [1].

Exploitation

An attacker must have local access to the system. The exploit involves sending a WM_SYSCOMMAND message with the SC_CLOSE command to the window handle of the protected process. No additional authentication or user interaction beyond local access is required [1].

Impact

By exploiting this vulnerability, a local attacker can terminate the protected process (2345MPCSafe.exe), effectively disabling the protection offered by the 2345 Security Guard. This could lead to a denial of service condition, as the security software's process is forcefully closed. The attacker gains the ability to bypass the software's process protection [1].

Mitigation

The vendor, Shanghai 2345, has not released a public patch or fixed version for this vulnerability as of the publication date (2018-05-04). No workaround is provided in the available references. Users are advised to consider alternative security software until an update is available [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.