CVE-2024-23439

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL codes of the Vba32m64.sys driver.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anti-virus:vba32:3.36.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 6.3
References () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory
References () https://www.anti-virus.by/vba32 - Product () https://www.anti-virus.by/vba32 - Product

17 Oct 2024, 15:10

Type Values Removed Values Added
First Time Anti-virus vba32
Anti-virus
CPE cpe:2.3:a:anti-virus:vba32:3.36.0:*:*:*:*:*:*:*
Summary
  • (es) Vba32 Antivirus v3.36.0 es afectado por una vulnerabilidad de lectura de memoria arbitraria al activar los códigos IOCTL 0x22201B, 0x22201F, 0x222023, 0x222027, 0x22202B, 0x22202F, 0x22203F, 0x222057 y 0x22205B del Controlador vba32m64.sys.
References () https://fluidattacks.com/advisories/adderley/ - () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory
References () https://www.anti-virus.by/vba32 - () https://www.anti-virus.by/vba32 - Product
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 7.1

13 Feb 2024, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 15:15

Updated : 2024-11-21 08:57


NVD link : CVE-2024-23439

Mitre link : CVE-2024-23439

CVE.ORG link : CVE-2024-23439


JSON object : View

Products Affected

anti-virus

  • vba32
CWE
CWE-125

Out-of-bounds Read