CVE-2024-23440

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
13/02/2024
Last modified:
19/05/2025

Description

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 of memory from ar arbitrary user-supplied pointer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:anti-virus:vba32:3.36.0:*:*:*:*:*:*:*