Sceawere

Vulnerability Detail

CVE-2026-19193UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Jiangmin Antivirus kvcore.sys Access Control Flaw

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Jiangmin
Product
Antivirus
Attack Type
Improper Access Controls
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-07T05:17:01.710Z",
  "pubdate": "2026-08-07T05:17:01.710Z",
  "executiveSummary": "A local privilege escalation and improper access control vulnerability has been identified within Jiangmin Antivirus 21. The security defect specifically resides in the MessageNotifyCallback function implemented within the kvcore.sys kernel-mode library, which forms a core component of the Minifilter Port architecture.\nSuccessful exploitation of this flaw allows an unprivileged local attacker to interact improperly with kernel-level components, potentially leading to unauthorized resource access or modifications. The risk implications are severe due to the execution context residing within ring 0 (kernel space), where memory corruption or arbitrary access primitives can compromise the integrity of the entire operating system.\nThe attack vector requires local access to the target host where Jiangmin Antivirus 21 is installed. A public exploit has already been published, increasing the operational risk of active exploitation in the wild. The vendor was notified of the vulnerability disclosures in advance but failed to provide any response or official remediation patches.\nMitigation options are strictly limited due to the lack of vendor response and patch availability, necessitating defensive hardening and compensatory controls at the host operating system level.",
  "technicalDetails": "The vulnerability exists in the Minifilter Port component of Jiangmin Antivirus 21, specifically within the kvcore.sys kernel driver. The flaw stems from improper access controls enforced within the MessageNotifyCallback function, which handles communication and data exchange between user-mode applications and the kernel-mode minifilter driver.\nMinifilter communication ports rely on secure descriptor validation and appropriate access checks to ensure that only authorized processes can send or receive messages via kernel ports. In this instance, the MessageNotifyCallback function fails to adequately validate the privileges, integrity, or origin of incoming requests or context structures passed through the Minifilter Port interface.\nTo execute an attack, an adversary must achieve local execution on the target system with user-level privileges. The attacker leverages the published exploit code to interact programmatically with the exposed minifilter communication port managed by kvcore.sys. By sending crafted input or malicious control messages to the driver, the attacker bypasses intended security boundaries enforced by the driver.\nBecause the vulnerable code executes within the context of kvcore.sys, which operates in ring 0 (kernel mode), improper access controls can lead to severe security implications. The flaw allows unauthorized interactions with sensitive kernel operations, potentially granting the local attacker elevated privileges, arbitrary read/write capabilities within kernel memory, or the ability to disrupt kernel stability (BSOD).\nAuthentication and privilege requirements for exploitation are minimal: the attacker requires local interactive or programmatic access to the host operating system, but no prior administrative privileges are strictly necessary to interface with improperly secured minifilter communication ports exposed by third-party security software. The network exposure is entirely local, as minifilter communication ports are not directly accessible over network protocols."
}
CVE-2026-19193: Jiangmin Antivirus kvcore.sys Access Control Flaw (HIGH Severity, CVSS: 7.8) - Sceawere