CVE-2021-31727
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x80002010 and send these IOCTL's to escalate privileges by overwriting the boot sector or overwriting critical code in the pagefile.
Un control de acceso incorrecto en las bibliotecas zam64.sys, zam32.sys en MalwareFox AntiMalware versión 2.74.0.150, donde 0x80002014, 0x80002018 de IOCTL exponen capacidades de lectura y escritura de disco sin restricciones, respectivamente. Un proceso no privilegiado puede abrir un identificador para \.\ZemanaAntiMalware, registrarse con el controlador usando IOCTL 0x80002010 y enviar estos IOCTL para escalar privilegios sobrescribiendo el sector de arranque o sobrescribiendo el código crítico en el pagefile
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-23 CVE Reserved
- 2021-05-17 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/irql0/CVE-2021-31728/blob/master/CVE-2021-31727.md | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Malwarefox Search vendor "Malwarefox" | Antimalware Search vendor "Malwarefox" for product "Antimalware" | 2.74.0.150 Search vendor "Malwarefox" for product "Antimalware" and version "2.74.0.150" | - |
Affected
|