Lucene search

K
nvd[email protected]NVD:CVE-2023-0907
HistoryFeb 18, 2023 - 8:15 a.m.

CVE-2023-0907

2023-02-1808:15:42
CWE-404
web.nvd.nist.gov
3
filseclab twister antivirus
vulnerability
denial of service
iocontrolcode handler

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

MULTIPLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:M/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

4.9

Confidence

High

EPSS

0

Percentile

13.3%

A vulnerability, which was classified as problematic, has been found in Filseclab Twister Antivirus 8.17. Affected by this issue is the function 0x220017 in the library ffsmon.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221456.

Affected configurations

Nvd
Node
filseclabtwister_antivirusMatch8.17
VendorProductVersionCPE
filseclabtwister_antivirus8.17cpe:2.3:a:filseclab:twister_antivirus:8.17:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

MULTIPLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:M/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

4.9

Confidence

High

EPSS

0

Percentile

13.3%

Related for NVD:CVE-2023-0907