Show filters
194 Total Results
Displaying 11-20 of 194
Sort by:
Attacker Value
Unknown

CVE-2023-1490

Disclosure Date: March 18, 2023 (last updated October 08, 2023)
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the library SDActMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223376.
Attacker Value
Unknown

CVE-2023-1453

Disclosure Date: March 17, 2023 (last updated October 08, 2023)
A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223298 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1446

Disclosure Date: March 17, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic was found in Watchdog Anti-Virus 1.4.214.0. Affected by this vulnerability is the function 0x80002004/0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223291.
Attacker Value
Unknown

CVE-2022-38582

Disclosure Date: November 04, 2022 (last updated December 22, 2024)
Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files.
Attacker Value
Unknown

CVE-2022-38611

Disclosure Date: September 16, 2022 (last updated October 08, 2023)
Incorrect access control in Watchdog Anti-Virus v1.4.158 allows attackers to perform a DLL hijacking attack and execute arbitrary code via a crafted binary.
Attacker Value
Unknown

CVE-2022-27534

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).
Attacker Value
Unknown

CVE-2021-27223

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS
Attacker Value
Unknown

CVE-2021-26624

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.
Attacker Value
Unknown

CVE-2020-10947

Disclosure Date: April 17, 2020 (last updated February 21, 2025)
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
Attacker Value
Unknown

CVE-2019-19382

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achieve privilege escalation.