CVE-2024-23439: Vba32 Antivirus v3.36.0 - Arbitrary Memory Read
Published Feb 13, 2024
·Updated
Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL codes of the Vba32m64.sys driver.
Affected Software
1 affected component
Anti-Virus VBA32=3.36.0
Event History
Feb 13, 2024
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23439?
CVE-2024-23439 has a critical severity rating due to its potential for arbitrary memory read vulnerabilities.
2
How do I fix CVE-2024-23439?
To fix CVE-2024-23439, update Vba32 Antivirus to the latest version that addresses this vulnerability.
3
Which version of Vba32 is affected by CVE-2024-23439?
Vba32 Antivirus version 3.36.0 is the only affected version for CVE-2024-23439.
4
What are the IOCTL codes that trigger CVE-2024-23439?
CVE-2024-23439 is triggered by the IOCTL codes 0x22201B, 0x22201F, 0x222023, 0x222027, 0x22202B, 0x22202F, 0x22203F, 0x222057, and 0x22205B.
5
Who is the vendor of the software affected by CVE-2024-23439?
The vendor of the software affected by CVE-2024-23439 is VirusBlokAda.