CVE-2018-16722: Input Validation
Published Nov 23, 2020
·Updated
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x12360094, a related issue to CVE-2018-16305.
Affected Software
1 affected component
V-secure Jingyun Antivirus=2.4.2.39
Event History
Nov 23, 2020
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16722?
CVE-2018-16722 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2018-16722?
To fix CVE-2018-16722, ensure you upgrade to a version of Jingyun Antivirus that addresses this vulnerability.
3
What types of attacks can exploit CVE-2018-16722?
CVE-2018-16722 can be exploited to trigger a denial of service resulting in a Blue Screen of Death (BSOD).
4
Which software is affected by CVE-2018-16722?
CVE-2018-16722 specifically affects Jingyun Antivirus version 2.4.2.39.
5
What component of Jingyun Antivirus does CVE-2018-16722 involve?
CVE-2018-16722 involves the driver file ZySandbox.sys.