Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2017-8339 : Exploit Details and Defense Strategies

Learn about CVE-2017-8339, a vulnerability in Panda Free Antivirus 18.0 allowing local users to trigger a denial of service attack resulting in a Blue Screen of Death (BSoD) by sending a malicious DeviceIoControl request.

A vulnerability in the PSKMAD.sys file within Panda Free Antivirus 18.0 can allow local users to trigger a denial of service attack resulting in a Blue Screen of Death (BSoD) by sending a malicious DeviceIoControl request.

Understanding CVE-2017-8339

This CVE entry describes a specific vulnerability in Panda Free Antivirus 18.0 that can be exploited by local users to cause a BSoD.

What is CVE-2017-8339?

The vulnerability in the PSKMAD.sys file of Panda Free Antivirus 18.0 enables local users to execute a denial of service attack leading to a BSoD by submitting a crafted DeviceIoControl request to the \.\PSMEMDriver endpoint.

The Impact of CVE-2017-8339

The exploitation of this vulnerability can result in a BSoD, causing disruption and potential data loss for affected systems.

Technical Details of CVE-2017-8339

This section provides more technical insights into the vulnerability.

Vulnerability Description

The PSKMAD.sys file in Panda Free Antivirus 18.0 allows local users to trigger a denial of service (BSoD) through a specifically crafted DeviceIoControl request to \.\PSMEMDriver.

Affected Systems and Versions

        Product: Panda Free Antivirus 18.0
        Vendor: Panda
        Version: Not applicable

Exploitation Mechanism

The vulnerability can be exploited by local users sending a malicious DeviceIoControl request to the \.\PSMEMDriver endpoint.

Mitigation and Prevention

Protecting systems from CVE-2017-8339 requires immediate actions and long-term security practices.

Immediate Steps to Take

        Disable or restrict access to the affected PSKMAD.sys file and \.\PSMEMDriver endpoint.
        Implement the latest security updates provided by Panda.

Long-Term Security Practices

        Regularly update antivirus software to patch known vulnerabilities.
        Educate users on safe computing practices to prevent exploitation of system weaknesses.
        Monitor system logs for any suspicious activities that could indicate an attack.
        Consider implementing additional security measures such as intrusion detection systems.

Patching and Updates

Ensure that Panda Free Antivirus is updated to the latest version to mitigate the vulnerability in PSKMAD.sys.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now