Description
Local attackers can trigger a stack-based buffer overflow on vulnerable installations of Antiy-AVL ATool security management v1.0.0.22. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x80002000 by the IRPFile.sys Antiy-AVL ATool kernel driver. The bug is caused by failure to properly validate the length of the user-supplied data, which results in a kernel stack buffer overflow. An attacker can leverage this vulnerability to execute arbitrary code in the context of the kernel, which could lead to privilege escalation and a failed exploit could lead to denial of service.
In plain language
AI Worth attentionAntiy-AVL ATool security management v1.0.0.22 has a flaw that can let someone already using a computer gain full control of it, so affected business systems should be reviewed promptly.
A local, low-privileged attacker can exploit improper IOCTL input-length validation in the IRPFile.sys kernel driver to cause a stack-based buffer overflow and execute code as the kernel.
What to do now
- Check whether any business computer runs Antiy-AVL ATool security management v1.0.0.22.
- Ask your IT provider or Antiy-AVL for a supported update; no fixed version or vendor patch is currently known.
- Until guidance is available, limit access to affected computers to trusted users and investigate unexpected system crashes or privilege changes.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-19650 and every CVE in our database. Create a free account — no credit card required.
Create Free Account