A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2018/Mar/78 | third party advisory mailing list |