Vulnerability Description
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ikarussecurity | Anti.Virus | 2.16.7 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/144955/IKARUS-AntiVirus-2.16.7-Privilege-EsThird Party AdvisoryVDB Entry
- https://theevilbit.blogspot.co.uk/2017/11/turning-cve-2017-14961-ikarus-antiviruExploitThird Party Advisory
- https://www.exploit-db.com/exploits/43139/Third Party AdvisoryVDB Entry
- https://www.ikarussecurity.com/about-ikarus/security-blog/vulnerability-in-windoVendor Advisory
- http://packetstormsecurity.com/files/144955/IKARUS-AntiVirus-2.16.7-Privilege-EsThird Party AdvisoryVDB Entry
- https://theevilbit.blogspot.co.uk/2017/11/turning-cve-2017-14961-ikarus-antiviruExploitThird Party Advisory
- https://www.exploit-db.com/exploits/43139/Third Party AdvisoryVDB Entry
- https://www.ikarussecurity.com/about-ikarus/security-blog/vulnerability-in-windoVendor Advisory
FAQ
What is CVE-2017-14961?
CVE-2017-14961 is a vulnerability with a CVSS score of 7.8 (HIGH). In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c.
How severe is CVE-2017-14961?
CVE-2017-14961 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14961?
Check the references section above for vendor advisories and patch information. Affected products include: Ikarussecurity Anti.Virus.