CVE-2017-15921
HIGHWatchdog Anti-Malware and Online Security Pro 2.74.186.150 - NULL Pointer Dereference via ioctl 0x80002010
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15921. PoCs published by Parvez Anwar.
AI-analyzed exploit summary This exploit triggers a null pointer dereference in the Watchdog Development Anti-Malware driver (zam32.sys) via IOCTL 0x80002010 or 0x80002054, causing a denial-of-service (BSOD) on 32-bit Windows 7 SP1.
Description
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002010. This is due to the input buffer being NULL or the input buffer size being 0 as they are not validated.
Exploits (1)
This exploit triggers a null pointer dereference in the Watchdog Development Anti-Malware driver (zam32.sys) via IOCTL 0x80002010 or 0x80002054, causing a denial-of-service (BSOD) on 32-bit Windows 7 SP1.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H