Vulnerabilidad · Publicado 07/08/2026
Se ha identificado una falla en la función MessageNotifyCallback del componente Minifilter Port (kvcore.sys) de Jiangmin Antivirus 21 que permite eludir controles de acceso mediante ejecución local. El exploit está públicamente disponible y activo en la naturaleza. El fabricante no ha respondido a notificaciones tempranas de divulgación, dejando a usuarios en LATAM sin parches oficiales confirmados.
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Score: 7.8/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-266, CWE-284
Publicado en NIST NVD.