CVE-2024-23440

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 of memory from ar arbitrary user-supplied pointer.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anti-virus:vba32:3.36.0:*:*:*:*:*:*:*

History

19 May 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 7.1

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory
References () https://www.anti-virus.by/vba32 - Product () https://www.anti-virus.by/vba32 - Product
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 6.3

17 Oct 2024, 15:08

Type Values Removed Values Added
First Time Anti-virus
Anti-virus vba32
CPE cpe:2.3:a:anti-virus:vba32:3.36.0:*:*:*:*:*:*:*
Summary
  • (es) Vba32 Antivirus v3.36.0 es afectado por una vulnerabilidad de lectura de memoria arbitraria. El código IOCTL 0x22200B del controlador Vba32m64.sys permite leer hasta 0x802 de memoria desde un puntero arbitrario proporcionado por el usuario.
References () https://fluidattacks.com/advisories/adderley/ - () https://fluidattacks.com/advisories/adderley/ - Third Party Advisory
References () https://www.anti-virus.by/vba32 - () https://www.anti-virus.by/vba32 - Product
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 7.1

13 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 15:15

Updated : 2025-05-19 19:15


NVD link : CVE-2024-23440

Mitre link : CVE-2024-23440

CVE.ORG link : CVE-2024-23440


JSON object : View

Products Affected

anti-virus

  • vba32
CWE
CWE-125

Out-of-bounds Read