VulnerabilityModified
CVE-2023-1492
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1.
MEDIUM 5.5EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been declared as problematic. This vulnerability affects the function 0x220019 in the library MaxProc64.sys of the component IoControlCode Handler. The manipulation of the argument SystemBuffer leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223378 is the identifier assigned to this vulnerability.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- maxpcsecure/anti virus plus
- Source
- cna@vuldb.com
References
- https://drive.google.com/file/d/1G_Szy4kCrZU-whGbVcxpdE1yKf5Vxqq3/viewExploit
- https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/CVE-2023-1492Exploit, Third Party Advisory
- https://vuldb.com/?ctiid.223378Permissions Required, Third Party Advisory
- https://vuldb.com/?id.223378Third Party Advisory
- https://drive.google.com/file/d/1G_Szy4kCrZU-whGbVcxpdE1yKf5Vxqq3/viewExploit
- https://github.com/zeze-zeze/WindowsKernelVuln/tree/master/CVE-2023-1492Exploit, Third Party Advisory
- https://vuldb.com/?ctiid.223378Permissions Required, Third Party Advisory
- https://vuldb.com/?id.223378Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.