CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-23439: Vba32 Antivirus v3.36.0 - Arbitrary Memory Read

7.1 CVSS

Description

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL codes of the Vba32m64.sys driver.

Classification

CVE ID: CVE-2024-23439

CVSS Base Severity: HIGH

CVSS Base Score: 7.1

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Problem Types

CWE-125 Out-of-bounds Read

Affected Products

Vendor: VirusBlokAda

Product: Vba32 Antivirus

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.01% (probability of being exploited)

EPSS Percentile: 1.03% (scored less or equal to compared to others)

EPSS Date: 2025-06-15 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-23439
https://fluidattacks.com/advisories/adderley/
https://www.anti-virus.by/vba32

Timeline