CVE-2019-14694: Race Condition
A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRPMJCLEANUP requests in the minifilter for directory change notifications. This allows an attacker to cause a denial of service (BSOD) when an executable is run inside the container.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14694?
CVE-2019-14694 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2019-14694?
To mitigate CVE-2019-14694, users should update to the latest version of Comodo Antivirus that addresses this vulnerability.
What does the CVE-2019-14694 vulnerability affect?
CVE-2019-14694 affects Comodo Antivirus version 12.0.0.6870 specifically due to a flaw in its sandbox container.
What type of issue is CVE-2019-14694?
CVE-2019-14694 is a use-after-free vulnerability caused by a race condition in handling cleanup requests.
What could be the consequence of exploiting CVE-2019-14694?
Exploitation of CVE-2019-14694 could lead to a denial of service, potentially causing a Blue Screen of Death (BSOD).