Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3973

Опубликовано: 17 июл. 2019
Источник: nvd
CVSS3: 5.5
CVSS2: 4.9
EPSS Низкий

Описание

Comodo Antivirus versions 11.0.0.6582 and below are vulnerable to Denial of Service affecting CmdGuard.sys via its filter port "cmdServicePort". A low privileged process can crash CmdVirth.exe to decrease the port's connection count followed by process hollowing a CmdVirth.exe instance with malicious code to obtain a handle to "cmdServicePort". Once this occurs, a specially crafted message can be sent to "cmdServicePort" using "FilterSendMessage" API. This can trigger an out-of-bounds write if lpOutBuffer parameter in FilterSendMessage API is near the end of specified buffer bounds. The crash occurs when the driver performs a memset operation which uses a size beyond the size of buffer specified, causing kernel crash.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:comodo:antivirus:*:*:*:*:*:*:*:*
Версия до 11.0.0.6582 (включая)

EPSS

Процентиль: 15%
0.00049
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

Comodo Antivirus versions 11.0.0.6582 and below are vulnerable to Denial of Service affecting CmdGuard.sys via its filter port "cmdServicePort". A low privileged process can crash CmdVirth.exe to decrease the port's connection count followed by process hollowing a CmdVirth.exe instance with malicious code to obtain a handle to "cmdServicePort". Once this occurs, a specially crafted message can be sent to "cmdServicePort" using "FilterSendMessage" API. This can trigger an out-of-bounds write if lpOutBuffer parameter in FilterSendMessage API is near the end of specified buffer bounds. The crash occurs when the driver performs a memset operation which uses a size beyond the size of buffer specified, causing kernel crash.

EPSS

Процентиль: 15%
0.00049
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-787