Malwarefox Antimalware vulnerabilities
4 known vulnerabilities affecting malwarefox/antimalware.
Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH4
Vulnerabilities
Page 1 of 1
CVE-2021-31728P2HIGHCVSS 7.8Exploitedv2.74.0.1502021-05-17
CVE-2021-31728 [HIGH] CVE-2021-31728: Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-p
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using th
nvd
CVE-2018-6606P3HIGHCVSS 7.8PoCv2.74.0.1502018-02-04
CVE-2018-6606 [HIGH] CWE-732 CVE-2018-6606: An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys a
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by sending IOCTL 0x80002010 and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.
nvd
CVE-2018-6593P3HIGHCVSS 7.8PoCv2.74.0.1502018-02-03
CVE-2018-6593 [HIGH] CWE-732 CVE-2018-6593: An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys a
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by connecting to the filter communication port and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.
nvd
CVE-2021-31727P3HIGHCVSS 7.8v2.74.0.1502021-05-17
CVE-2021-31727 [HIGH] CVE-2021-31727: Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x80002010 and send these IOCTL's to escalate privileges by overwriting
nvd