Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 of memory from ar arbitrary user-supplied pointer.
References
Link | Resource |
---|---|
https://fluidattacks.com/advisories/adderley/ | Third Party Advisory |
https://www.anti-virus.by/vba32 | Product |
https://fluidattacks.com/advisories/adderley/ | Third Party Advisory |
https://www.anti-virus.by/vba32 | Product |
Configurations
History
21 Nov 2024, 08:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory | |
References | () https://www.anti-virus.by/vba32 - Product | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
17 Oct 2024, 15:08
Type | Values Removed | Values Added |
---|---|---|
First Time |
Anti-virus
Anti-virus vba32 |
|
CPE | cpe:2.3:a:anti-virus:vba32:3.36.0:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
References | () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory | |
References | () https://www.anti-virus.by/vba32 - Product |
13 Feb 2024, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-13 15:15
Updated : 2024-11-21 08:57
NVD link : CVE-2024-23440
Mitre link : CVE-2024-23440
CVE.ORG link : CVE-2024-23440
JSON object : View
Products Affected
anti-virus
- vba32
CWE
CWE-125
Out-of-bounds Read