MalwareFox AntiMalware 2.74.0.150 contains an improper access control vulnerability in its kernel drivers zam32.sys and zam64.sys. A non-privileged user can interact with the driver via IOCTL 0x80002010 to register itself, and subsequently use IOCTL 0x8000204C to the device \.\ZemanaAntiMalware to escalate privileges to SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a small standalone Windows local exploit repository for CVE-2018-6606, not part of a larger framework. The repository contains five files: a README with build/use notes, a Makefile for MinGW compilation, a VS Code task file, a Windows resource script, and the main C source. The core logic is entirely in main.c. The exploit’s purpose is to abuse a vulnerable Zemana AntiMalware kernel driver to terminate an arbitrary process specified on the command line. It does this by embedding a driver binary as an RCDATA resource, extracting that driver to C:\Windows\System32\drivers\dot_sys.sys, creating a kernel-driver service named dot_sys, starting the service, and then opening the device \\.\ZemanaAntiMalware. After opening the device, it sends two DeviceIoControl requests: IOCTL 0x80002010 with the current process PID, likely to establish authorization or context, and IOCTL 0x80002048 with the attacker-supplied target PID, which triggers the process termination primitive. Repository structure is straightforward: resource.rc defines the embedded driver resource name IOC_THIS and references the original local path of the .sys file used at build time; main.c implements resource extraction, service creation, driver startup, device access, and IOCTL dispatch; Makefile builds the executable and resource object; .vscode/tasks.json provides convenience build/cleanup tasks including deleting the service. The README states the exploit was tested on Windows 10 64-bit and requires administrator privileges. Overall, this is an operational local proof-of-concept exploit for a vulnerable signed/installed driver abuse scenario. It does not provide a shell or remote access; its main capability is arbitrary process killing through a kernel driver interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.