Vulnerability Description
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002054. This is due to the input buffer being NULL or the input buffer size being 0 as they are not validated.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchdogdevelopment | Anti-Malware | 2.74.186.150 |
| Watchdogdevelopment | Online Security Pro | 2.74.186.150 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/144786/Watchdog-Development-Anti-Malware-OnExploitIssue TrackingThird Party Advisory
- https://www.exploit-db.com/exploits/43058/ExploitIssue TrackingThird Party Advisory
- http://packetstormsecurity.com/files/144786/Watchdog-Development-Anti-Malware-OnExploitIssue TrackingThird Party Advisory
- https://www.exploit-db.com/exploits/43058/ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2017-15920?
CVE-2017-15920 is a vulnerability with a CVSS score of 7.5 (HIGH). In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioct...
How severe is CVE-2017-15920?
CVE-2017-15920 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15920?
Check the references section above for vendor advisories and patch information. Affected products include: Watchdogdevelopment Anti-Malware, Watchdogdevelopment Online Security Pro.