HIGH

CVE-2021-31728

CVSS v3

7.8

HIGH

EPSS Score

22.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \\.\\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using this hook with IOCTL 0x80002014 or 0x80002018, this exposes ring 0 code execution in the context of the driver allowing the non-privileged process to elevate privileges.

Technical details

Published
5/17/2021

Frequently asked questions

What is CVE-2021-31728?

Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \\.\\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using this hook with IOCTL 0x80002014 or 0x80002018, this exposes ring 0 code execution in the context of the driver allowing the non-privileged process to elevate privileges.

Is CVE-2021-31728 actively exploited?

Active exploitation of CVE-2021-31728 has not been confirmed. The EPSS score is 22.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-31728?

CVE-2021-31728 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2021-31728 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.