9.8
CVSSv3

CVE-2018-5701

Published: 31/01/2018 Updated: 15/02/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

iolo system shield 5.0.0.136

Exploits

/* Exploit Title - System Shield AntiVirus & AntiSpyware Arbitrary Write Privilege Escalation Date - 29th January 2018 Discovered by - Parvez Anwar (@parvezghh) Vendor Homepage - wwwiolocom/ Tested Version - 500136 Driver Version - 54111 - ampsys Tested on OS - 64bit Windows 7 and Windows 10 (1709) C ...
System Shield version 500136 suffers from a privilege escalation vulnerability ...