Watchdog Antivirus v1.6.415 - DoS
5.5
Medium
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Watchdog Antivirus v1.6.415 - Denial of Service
Code name
State
Public
Release date
Apr 22, 2024
Affected product
Watchdog Antivirus
Vendor
Watchdog
Affected version(s)
Version 1.6.415
Vulnerability name
Denial of Service (DoS)
Vulnerability type
Remotely exploitable
No
CVSS v3.0 vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v3.0 base score
5.5
Exploit available
Yes
CVE ID(s)
Description
Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014
IOCTL code of the wsdk-driver.sys
driver.
Vulnerability
The 0x80002014
IOCTL code of the wsdk-driver.sys
driver allows to perform a Denial of Service, leading to a BSOD of the affected computer caused by a NULL pointer dereference.
The disassembled vulnerable function is sub_140008D5C
:
The sub_140008D5C
function tries to find the process instance of the WAV.exe
executable. It receives a parameter called ProcessId
at [1]
, tries to find the image filename with PsGetProcessImageFileName
at [2]
and compares if the file name matches with WAV.exe
using stricmp()
at [3]
. However, the parameter ProcessId
can be controlled by the attacker, making the result of PsGetProcessImageFileName
to be NULL
, performing an invalid comparison with stricmp()
, resulting in a NULL pointer dereference:
Our security policy
We have reserved the ID CVE-2024-1241 to refer to this issue from now on.
System Information
Version: Watchdog Antivirus v1.6.415
Operating System: Windows
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://watchdog.dev/
Product page https://watchdog.dev/solutions/anti-virus/
Timeline
Vulnerability discovered
Feb 5, 2024
Vendor contacted
Feb 5, 2024
Vendor replied
Mar 3, 2024
Public disclosure
Apr 22, 2024