Vulnerabilities > CVE-2019-19820 - Release of Invalid Pointer or Reference vulnerability in Kyrol Internet Security 9.0.6.9
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read primitive.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |