Description
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-07
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Jiangmin Antivirus version 21 allows a local attacker to manipulate the MessageNotifyCallback function in kvcore.sys, resulting in improper access controls consistent with CWE-266 and CWE-284. An attacker who gains local execution rights can bypass expected permissions, potentially elevating privileges or accessing protected resources on the machine.

Affected Systems

The vulnerability affects Jiangmin Antivirus 21. Users running this version are at risk, as the Minifilter Port component’s kvcore.sys library is compromised.

Risk and Exploitability

With a CVSS score of 8.5, the flaw poses a high severity threat. The EPSS score is unavailable, but the vulnerability is publicly documented and an exploit exists, indicating readiness to be used by threat actors. It requires local access, so the risk is confined to systems where an attacker can execute code locally. The vulnerability is not listed in CISA KEV, yet organizations must treat it as a serious local privilege escalation risk.

Generated by OpenCVE AI on August 7, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version of Jiangmin Antivirus that includes a fix for the MessageNotifyCallback flaw.
  • If no patch is yet available, disable or uninstall the Minifilter Port component (kvcore.sys) until a remediation is released.
  • Enforce least‑privilege policies for local user accounts and isolate systems running Jiangmin Antivirus from critical assets; monitor system logs for suspicious MessageNotifyCallback activity.

Generated by OpenCVE AI on August 7, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
First Time appeared Jiangmin
Jiangmin antivirus
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:jiangmin:antivirus:*:*:*:*:*:*:*:*
Vendors & Products Jiangmin
Jiangmin antivirus
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jiangmin Antivirus
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T04:15:10.378Z

Reserved: 2026-08-06T20:06:03.663Z

Link: CVE-2026-19193

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T05:30:07Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control