Sceawere
Vulnerability Detail
CVE-2026-19195UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
V-Secure Jingyun Antivirus ZyArk.sys Access Control Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- V-Secure
- Product
- Jingyun Antivirus
- Attack Type
- Improper Access Controls
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-08-07T05:17:01.890Z",
"pubdate": "2026-08-07T05:17:01.890Z",
"executiveSummary": "An improper access control vulnerability has been identified in V-Secure Jingyun Antivirus version 2.4.2.39. The flaw resides within the ZyArk.sys kernel driver component, specifically affecting an unknown internal function. This security defect allows local attackers to manipulate system resources due to insufficient validation and access restriction enforcement within the driver interface.\nThe impact of successful exploitation includes unauthorized privilege escalation, arbitrary kernel-level read and write operations, and potential compromise of the underlying operating system. Because the affected component operates at the highest privilege level (Ring 0), exploitation compromises the entire integrity and confidentiality of the host machine. The attack vector requires local access to the target system.\nPublic disclosure of the exploit increases the likelihood of active targeting, particularly given that the vendor failed to respond to early vulnerability notifications. Organizations utilizing the affected software face elevated risk until appropriate remediation or containment measures are implemented.",
"technicalDetails": "The vulnerability exists within the ZyArk.sys kernel driver of V-Secure Jingyun Antivirus 2.4.2.39, specifically stemming from improper access controls implemented in an unspecified input-output control (IOCTL) or communication interface. Kernel drivers typically expose communication channels via device objects that user-mode applications can interact with using APIs such as DeviceIoControl.\nIn this specific vulnerability, the root cause is the failure of the ZyArk.sys driver to adequately validate the security context, privileges, or integrity of incoming requests from user-mode processes before executing sensitive operations. Because the driver executes in kernel space (Ring 0), an unprivileged or low-privileged local user can interact with the exposed device interface to issue malicious requests.\nThe attack flow proceeds as follows: First, an attacker establishes local execution access on the target system running V-Secure Jingyun Antivirus 2.4.2.39. Second, the attacker deploys a crafted exploit payload designed to communicate directly with the ZyArk.sys driver interface. Third, by sending specially crafted IOCTL requests or parameters to the vulnerable function within ZyArk.sys, the attacker bypasses standard OS security boundaries. Fourth, the driver processes the unvalidated input, permitting unauthorized actions such as arbitrary kernel memory manipulation, tampering with security products, or executing arbitrary code with kernel-level privileges.\nAuthentication and privilege requirements are limited to local system access, meaning an attacker does not require remote network exposure or initial high-privilege credentials to initiate the attack. However, execution of code in the local environment is required. The post-exploitation impact is severe, often leading to complete system compromise, disabling of security controls, kernel panics, or persistent backdoors embedded within the operating system kernel."
}