Description
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-07
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the ZyArk.sys kernel driver of V‑Secure Jingyun Antivirus, enabling a local attacker to manipulate an undisclosed function and bypass the driver’s access controls, potentially elevating privileges. The impact is the compromise of system integrity and confidentiality through local privilege escalation. The weakness is classified as improper privilege management and improper access control (CWE‑266 and CWE‑284).

Affected Systems

Affected is V‑Secure Jingyun Antivirus version 2.4.2.39, a Windows security product that includes the ZyArk.sys kernel driver. The vulnerability resides in an undocumented function of this driver, allowing local users to bypass its access controls.

Risk and Exploitability

The CVSS score is 8.5, indicating a high severity vulnerability. EPSS is not available, and the vulnerability is not in the CISA KEV catalog. Attack vectors are local; the description states that exploitation requires local privilege. Given the public disclosure and lack of vendor response, the risk remains high and exploitation is plausible via local access. Prompt remediation is recommended to mitigate potential privilege escalation.

Generated by OpenCVE AI on August 7, 2026 at 06:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the vendor‑supplied update that addresses the ZyArk.sys access control flaw.
  • If no update is available, uninstall or disable the kernel driver to eliminate the attack surface.
  • Apply least‑privilege principles by restricting local user accounts that can load kernel drivers, and enable system monitoring to detect unauthorized driver registrations.

Generated by OpenCVE AI on August 7, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
References

Sun, 09 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
References

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
First Time appeared V-secure
V-secure jingyun Antivirus
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:v-secure:jingyun_antivirus:*:*:*:*:*:*:*:*
Vendors & Products V-secure
V-secure jingyun Antivirus
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

V-secure Jingyun Antivirus
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-11T04:59:35.429Z

Reserved: 2026-08-06T20:09:41.698Z

Link: CVE-2026-19195

cve-icon Vulnrichment

Updated: 2026-08-07T15:28:09.517Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T05:17:01.890

Modified: 2026-08-12T20:59:21.023

Link: CVE-2026-19195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T07:00:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control