CVE-2026-94137: Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of service
A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub180004AC0 of the file shdrvx64.sys of the component IRPMJDEVICECONTROL Handler. The manipulation of the argument PID leads to denial of service. The attack must be carried out locally.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must have local access and low-level privileges on a system running the affected shzh version. The available information does not indicate that remote exploitation is possible.
What is the impact of successful exploitation?
Successful manipulation of the PID argument in the IRP_MJ_DEVICE_CONTROL handler can cause a denial of service. No confidentiality or integrity impact is indicated by the supplied severity vector.
Which component should be checked during triage?
Check systems running Hangzhou Shunwang Technology shzh 10.7.2.693 and inspect the shdrv_x64.sys driver, specifically its IRP_MJ_DEVICE_CONTROL handling path. The affected function is identified as sub_180004AC0.