2024-02-13 17:00:28 +00:00
{
"id" : "CVE-2024-23439" ,
"sourceIdentifier" : "help@fluidattacks.com" ,
"published" : "2024-02-13T15:15:08.850" ,
2024-10-17 16:03:26 +00:00
"lastModified" : "2024-10-17T15:10:21.260" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-02-13 17:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL codes of the Vba32m64.sys driver."
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Vba32 Antivirus v3.36.0 es afectado por una vulnerabilidad de lectura de memoria arbitraria al activar los c\u00f3digos IOCTL 0x22201B, 0x22201F, 0x222023, 0x222027, 0x22202B, 0x22202F, 0x22203F, 0x222057 y 0x22205B del Controlador vba32m64.sys."
2024-02-13 17:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-10-17 16:03:26 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.1 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.2
} ,
2024-02-13 17:00:28 +00:00
{
"source" : "help@fluidattacks.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 6.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.0 ,
"impactScore" : 5.2
}
]
} ,
"weaknesses" : [
{
"source" : "help@fluidattacks.com" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-125"
}
]
}
] ,
2024-10-17 16:03:26 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:anti-virus:vba32:3.36.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "00ECDEA3-9AF7-405E-B0BB-1EA693E52ACF"
}
]
}
]
}
] ,
2024-02-13 17:00:28 +00:00
"references" : [
{
"url" : "https://fluidattacks.com/advisories/adderley/" ,
2024-10-17 16:03:26 +00:00
"source" : "help@fluidattacks.com" ,
"tags" : [
"Third Party Advisory"
]
2024-02-13 17:00:28 +00:00
} ,
{
"url" : "https://www.anti-virus.by/vba32" ,
2024-10-17 16:03:26 +00:00
"source" : "help@fluidattacks.com" ,
"tags" : [
"Product"
]
2024-02-13 17:00:28 +00:00
}
]
}