VYPR

AntiMalware

by MalwareFox

CVEs (6)

  • CVE-2018-6606HigFeb 4, 2018
    risk 0.54cvss 7.8epss 0.01

    An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by sending IOCTL 0x80002010 and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate…

  • CVE-2018-6593HigFeb 3, 2018
    risk 0.54cvss 7.8epss 0.01

    An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by connecting to the filter communication port and then using IOCTL 0x8000204C to…

  • CVE-2021-31728HigMay 17, 2021
    risk 0.51cvss 7.8epss 0.03

    Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL…

  • CVE-2021-31727HigMay 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver…

  • CVE-2018-5714HigJan 16, 2018
    risk 0.51cvss 7.8epss 0.00

    In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002054.

  • CVE-2018-5713HigJan 16, 2018
    risk 0.51cvss 7.8epss 0.01

    In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002010.