CVE-2018-16720: Input Validation
Published Nov 23, 2020
·Updated
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x1236001c, a related issue to CVE-2018-16304.
Affected Software
1 affected component
V-secure Jingyun Antivirus=2.4.2.39
Event History
Nov 23, 2020
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16720?
CVE-2018-16720 has a severity rating that suggests it can lead to a denial of service condition.
2
How do I fix CVE-2018-16720?
To fix CVE-2018-16720, users should update Jingyun Antivirus to a patched version that resolves the input validation issue.
3
Who is affected by CVE-2018-16720?
CVE-2018-16720 affects users of Jingyun Antivirus version 2.4.2.39.
4
What does CVE-2018-16720 exploit?
CVE-2018-16720 exploits a vulnerability in the driver file ZySandbox.sys by not validating input values.
5
What are the potential impacts of CVE-2018-16720?
The potential impacts of CVE-2018-16720 include causing a BSOD and possibly other unspecified effects.