Description
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using this hook with IOCTL 0x80002014 or 0x80002018, this exposes ring 0 code execution in the context of the driver allowing the non-privileged process to elevate privileges.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:03:33.789Z
Reserved: 2021-04-23T00:00:00.000Z
Link: CVE-2021-31728
No data.
Status : Modified
Published: 2021-05-17T13:15:07.803
Modified: 2024-11-21T06:06:09.627
Link: CVE-2021-31728
No data.
OpenCVE Enrichment
No data.
Weaknesses