Vba32 Antivirus v3.36.0 - AMR
6.3
Medium
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Vba32 Antivirus v3.36.0 - Arbitrary Memory Read
Code name
State
Public
Release date
Jan 29, 2024
Affected product
Vba32 Antivirus
Vendor
VirusBlokAda
Affected version(s)
Version 3.36.0
Vulnerability name
Arbitrary Memory Read
Vulnerability type
Remotely exploitable
No
CVSS v3.0 vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS v3.0 base score
6.3
Exploit available
Yes
CVE ID(s)
Description
Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read (AMR) vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL codes of the Vba32m64.sys driver.
CVE-2024-23439
The 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL codes of the Vba32m64.sys
driver allows to perform a partial Arbitrary Memory Read. The attacker can control the address from where to perform the read by supplying an arbitrary pointer in the lpInBuffer
parameter of the IOCTL call, but there's currently not leak of the result of such read to user-space. However, the invalid address will cause a BSOD which leads to a Denial of Service of the affected computer.
CVE-2024-23440
The 0x22200B IOCTL code of the Vba32m64.sys
driver allows to read up to 0x802 of memory from ar arbitrary user-supplied pointer. The attacker can control the address from where to perform the read by supplying an arbitrary pointer in the lpInBuffer
parameter of the IOCTL call. The vulnerable IOCTL will copy up to 0x802 bytes to a global variable of the driver. There's not evidence of the leak of the result of such read to user-space. However, the invalid address will cause a BSOD which leads to a Denial of Service of the affected computer.
Our security policy
We have reserved the IDs CVE-2024-23439 and CVE-2024-23440 to refer to these issues from now on.
System Information
Version: Vba32 Antivirus v3.36.0
Operating System: Windows
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://www.anti-virus.by/
Product page https://www.anti-virus.by/vba32
Timeline
Vulnerability discovered
Jan 16, 2024
Vendor contacted
Jan 16, 2024
Vendor replied
Jan 18, 2024
Public disclosure
Jan 29, 2024