CVE-2018-6606
MalwareFox AntiMalware 2.74.0.150 - Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by sending IOCTL 0x80002010 and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.
Se ha descubierto un problema en la versión 2.74.0.150 de MalwareFox AntiMalware. Un control de acceso incorrecto en zam32.sys y zam64.sys permite que un proceso no privilegiado se registre a sí mismo en el controlador enviando una llamada IOCTL 0x80002010 y luego empleando otra llamada IOCTL 0x8000204C a \\.\ZemanaAntiMalware para elevar privilegios.
MalwareFox AntiMalware version 2.74.0.150 suffers from a local privilege escalation vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-03 CVE Reserved
- 2018-02-04 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/SouhailHammou/Exploits/blob/master/CVE-2018-6606/Malwarefox_privescl_1.c | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/43987 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Malwarefox Search vendor "Malwarefox" | Antimalware Search vendor "Malwarefox" for product "Antimalware" | 2.74.0.150 Search vendor "Malwarefox" for product "Antimalware" and version "2.74.0.150" | - |
Affected
|