Description
A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation of the argument PID leads to denial of service. The attack must be carried out locally.
Published: 2026-09-21
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the sub_180004AC0 function of the shdrv_x64.sys driver in Hangzhou Shunwang Technology shzh. By manipulating the PID argument passed to the IRP_MJ_DEVICE_CONTROL handler, an attacker can cause the driver to fail, resulting in a denial of service condition. The denial stops the driver and may cause associated services to become unresponsive.

Affected Systems

Hangzhou Shunwang Technology shzh version 10.7.2.693 is affected. Only local users with privileges to interact with the driver can exploit the flaw; no publicly available remote path is known.

Risk and Exploitability

The CVSS score is 4.8, indicating a moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, so immediate exploitation activity is not observed. However, because exploitation requires local access, personnel with local privileges can easily trigger the crash. The risk is medium, especially in environments that rely on the affected driver for critical operations.

Generated by OpenCVE AI on September 21, 2026 at 04:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or apply the vendor-provided patch that fixes the PID argument handling in shdrv_x64.sys.
  • If an update is unavailable, restrict local privileges for accounts that can send IRP_MJ_DEVICE_CONTROL requests to the driver, limiting the ability to manipulate the PID field.
  • Monitor device logs and system stability for unexpected crashes or service interruptions that may indicate an attempted exploitation.

Generated by OpenCVE AI on September 21, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation of the argument PID leads to denial of service. The attack must be carried out locally.
Title Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of service
First Time appeared Hangzhou Shunwang Technology
Hangzhou Shunwang Technology shzh
Weaknesses CWE-404
CPEs cpe:2.3:a:hangzhou_shunwang_technology:shzh:*:*:*:*:*:*:*:*
Vendors & Products Hangzhou Shunwang Technology
Hangzhou Shunwang Technology shzh
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Hangzhou Shunwang Technology Shzh
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T03:15:08.234Z

Reserved: 2026-09-20T19:31:12.060Z

Link: CVE-2026-94137

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T04:17:36.393

Modified: 2026-09-21T04:17:36.393

Link: CVE-2026-94137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release