505
VMScore

CVE-2017-15920

Published: 30/10/2017 Updated: 18/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002054. This is due to the input buffer being NULL or the input buffer size being 0 as they are not validated.

Vulnerable Product Search on Vulmon Subscribe to Product

watchdogdevelopment online security pro 2.74.186.150

watchdogdevelopment anti-malware 2.74.186.150

Exploits

/* Exploit Title - Watchdog Development Anti-Malware/Online Security Pro Null Pointer Dereference Date - 26th October 2017 Discovered by - Parvez Anwar (@parvezghh) Vendor Homepage - wwwwatchdogdevelopmentcom/ Tested Version - 274186150 Driver Version - 22163 - zam32sys Tested on OS - 32bit Windows 7 SP1 ...
Watchdog Development Anti-Malware / Online Security Pro version 274186150 suffers from a NULL pointer dereference vulnerability ...