Impact
A flaw in Jiangmin Antivirus version 21 allows a local attacker to manipulate the MessageNotifyCallback function in kvcore.sys, resulting in improper access controls consistent with CWE-266 and CWE-284. An attacker who gains local execution rights can bypass expected permissions, potentially elevating privileges or accessing protected resources on the machine.
Affected Systems
The vulnerability affects Jiangmin Antivirus 21. Users running this version are at risk, as the Minifilter Port component’s kvcore.sys library is compromised.
Risk and Exploitability
With a CVSS score of 8.5, the flaw poses a high severity threat. The EPSS score is unavailable, but the vulnerability is publicly documented and an exploit exists, indicating readiness to be used by threat actors. It requires local access, so the risk is confined to systems where an attacker can execute code locally. The vulnerability is not listed in CISA KEV, yet organizations must treat it as a serious local privilege escalation risk.
OpenCVE Enrichment