Impact
The vulnerability resides in the sub_180004AC0 function of the shdrv_x64.sys driver in Hangzhou Shunwang Technology shzh. By manipulating the PID argument passed to the IRP_MJ_DEVICE_CONTROL handler, an attacker can cause the driver to fail, resulting in a denial of service condition. The denial stops the driver and may cause associated services to become unresponsive.
Affected Systems
Hangzhou Shunwang Technology shzh version 10.7.2.693 is affected. Only local users with privileges to interact with the driver can exploit the flaw; no publicly available remote path is known.
Risk and Exploitability
The CVSS score is 4.8, indicating a moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, so immediate exploitation activity is not observed. However, because exploitation requires local access, personnel with local privileges can easily trigger the crash. The risk is medium, especially in environments that rely on the affected driver for critical operations.
OpenCVE Enrichment