CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-23440: Vba32 Antivirus v3.36.0 - Arbitrary Memory Read

7.1 CVSS

Description

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 of memory from ar arbitrary user-supplied pointer.

Classification

CVE ID: CVE-2024-23440

CVSS Base Severity: HIGH

CVSS Base Score: 7.1

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Problem Types

CWE-125 Out-of-bounds Read

Affected Products

Vendor: VirusBlokAda

Product: Vba32 Antivirus

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.01% (probability of being exploited)

EPSS Percentile: 1.03% (scored less or equal to compared to others)

EPSS Date: 2025-06-15 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-23440
https://fluidattacks.com/advisories/adderley/
https://www.anti-virus.by/vba32

Timeline