Vulnerabilities > CVE-2017-15920 - NULL Pointer Dereference vulnerability in Watchdogdevelopment Anti-Malware and Online Security PRO

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
watchdogdevelopment
CWE-476
exploit available

Summary

In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002054. This is due to the input buffer being NULL or the input buffer size being 0 as they are not validated.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionWatchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference. CVE-2017-15920,CVE-2017-15921. Dos exploit for Windows platform
fileexploits/windows/dos/43058.c
idEDB-ID:43058
last seen2017-10-27
modified2017-10-26
platformwindows
port
published2017-10-26
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43058/
titleWatchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference
typedos

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/144786/watchdogdam-null.txt
idPACKETSTORM:144786
last seen2017-10-27
published2017-10-27
reporterParvez Anwar
sourcehttps://packetstormsecurity.com/files/144786/Watchdog-Development-Anti-Malware-Online-Security-Pro-NULL-Pointer-Dereference.html
titleWatchdog Development Anti-Malware / Online Security Pro NULL Pointer Dereference