Sceawere
Vulnerability Detail
CVE-2026-19193UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Jiangmin Antivirus kvcore.sys Access Control Flaw
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Jiangmin
- Product
- Antivirus
- Attack Type
- Improper Access Controls
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-08-07T05:17:01.710Z",
"pubdate": "2026-08-07T05:17:01.710Z",
"executiveSummary": "A local privilege escalation and improper access control vulnerability has been identified within Jiangmin Antivirus 21. The security defect specifically resides in the MessageNotifyCallback function implemented within the kvcore.sys kernel-mode library, which forms a core component of the Minifilter Port architecture.\nSuccessful exploitation of this flaw allows an unprivileged local attacker to interact improperly with kernel-level components, potentially leading to unauthorized resource access or modifications. The risk implications are severe due to the execution context residing within ring 0 (kernel space), where memory corruption or arbitrary access primitives can compromise the integrity of the entire operating system.\nThe attack vector requires local access to the target host where Jiangmin Antivirus 21 is installed. A public exploit has already been published, increasing the operational risk of active exploitation in the wild. The vendor was notified of the vulnerability disclosures in advance but failed to provide any response or official remediation patches.\nMitigation options are strictly limited due to the lack of vendor response and patch availability, necessitating defensive hardening and compensatory controls at the host operating system level.",
"technicalDetails": "The vulnerability exists in the Minifilter Port component of Jiangmin Antivirus 21, specifically within the kvcore.sys kernel driver. The flaw stems from improper access controls enforced within the MessageNotifyCallback function, which handles communication and data exchange between user-mode applications and the kernel-mode minifilter driver.\nMinifilter communication ports rely on secure descriptor validation and appropriate access checks to ensure that only authorized processes can send or receive messages via kernel ports. In this instance, the MessageNotifyCallback function fails to adequately validate the privileges, integrity, or origin of incoming requests or context structures passed through the Minifilter Port interface.\nTo execute an attack, an adversary must achieve local execution on the target system with user-level privileges. The attacker leverages the published exploit code to interact programmatically with the exposed minifilter communication port managed by kvcore.sys. By sending crafted input or malicious control messages to the driver, the attacker bypasses intended security boundaries enforced by the driver.\nBecause the vulnerable code executes within the context of kvcore.sys, which operates in ring 0 (kernel mode), improper access controls can lead to severe security implications. The flaw allows unauthorized interactions with sensitive kernel operations, potentially granting the local attacker elevated privileges, arbitrary read/write capabilities within kernel memory, or the ability to disrupt kernel stability (BSOD).\nAuthentication and privilege requirements for exploitation are minimal: the attacker requires local interactive or programmatic access to the host operating system, but no prior administrative privileges are strictly necessary to interface with improperly secured minifilter communication ports exposed by third-party security software. The network exposure is entirely local, as minifilter communication ports are not directly accessible over network protocols."
}