CVE-2023-2874

MEDIUM

Twister Antivirus 8.0-8.16 - Denial of Service in IoControlCode Handler

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, has been found in Twister Antivirus 8. This issue affects the function 0x804f2158/0x804f2154/0x804f2150/0x804f215c/0x804f2160/0x80800040/0x804f214c/0x804f2148/0x804f2144/0x801120e4/0x804f213c/0x804f2140 in the library filppd.sys of the component IoControlCode Handler. The manipulation leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-229853 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.229853
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.229853

Scores

CVSS v3 5.5
EPSS 0.0032
EPSS Percentile 24.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-404
Status published
Products (1)
filseclab/twister_antivirus 8.0 - 8.17
Published May 24, 2023
Tracked Since Feb 18, 2026