An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a NULL Pointer Dereference vulnerability due to not validating the size of the output buffer value from IOCtl 0x80002028.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://www.greyhathacker.net | third party advisory exploit |
https://www.greyhathacker.net/?p=1025 | third party advisory exploit |