JiangMin Antivirus, kvcore.sys, DoS
Vulnerability Info
Version
- JiangMin Antivirus 16.2.2022.418, kvcore.sys 1.22.3.7
- https://www.jiangmin.com/plus/list.php?tid=65
Impact
Denial of Service
Description
From IoControlCode 0x222010, a normal user can cause DoS due to null pointer dereference on a local variable.
Reproduce
In the attached file DoS2.zip, there are DoS2.exe, DoS2.cpp, JMV21Web20220419.exe, and kvcore.sys. DoS2.exe is the PoC to cause BSOD where JMV21Web20220419.exe contains the vulnerable driver kvcore.sys installed, and DoS2.cpp is the source code of DoS2.exe. To reproduce the issue, install JMV21Web20220419.exe and execute DoS2.exe. It is expected that the system will crash (BSOD) once DoS2.exe is executed. Password for attachment: DoS2 https://drive.google.com/file/d/1Div9mElTdsluLrU2etziLYqmXcqQFj1j/view?usp=sharing