- JiangMin Antivirus 16.2.2022.418, kvcore.sys 1.22.3.7
- https://www.jiangmin.com/plus/list.php?tid=65
Denial of Service
From IoControlCode 0x222010, a normal user can cause DoS due to null pointer dereference on a local variable.
In the attached file DoS2.zip, there are DoS2.exe, DoS2.cpp, JMV21Web20220419.exe, and kvcore.sys. DoS2.exe is the PoC to cause BSOD where JMV21Web20220419.exe contains the vulnerable driver kvcore.sys installed, and DoS2.cpp is the source code of DoS2.exe. To reproduce the issue, install JMV21Web20220419.exe and execute DoS2.exe. It is expected that the system will crash (BSOD) once DoS2.exe is executed. Password for attachment: DoS2 https://drive.google.com/file/d/1Div9mElTdsluLrU2etziLYqmXcqQFj1j/view?usp=sharing