Security Advisory

CVE-2019-19820

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-12-16 20:07:36
Last updated 2024-08-05 02:25:12
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read primitive.