CVE-2021-31728 is an incorrect access control vulnerability in the Zemana-derived kernel drivers zam64.sys and zam32.sys shipped with MalwareFox AntiMalware 2.74.0.150. A non-privileged user-mode process can open a handle to the device \.\ZemanaAntiMalware and register itself with the driver via IOCTL 0x80002010. After registration, the process can abuse IOCTL 0x80002040 to allocate executable kernel memory, IOCTL 0x80002044 to install a hook, and IOCTL 0x80002014 or 0x80002018 to trigger execution of the attacker-controlled executable memory. The flaw is caused by insufficient access restrictions and trust validation in the driver's exposed device interface and privileged IOCTL handlers, allowing unprivileged callers to reach dangerous kernel functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains two main C-based proof-of-concept exploits targeting local privilege escalation vulnerabilities in MalwareFox AntiMalware 2.74.0.150 (CVE-2021-31727 and CVE-2021-31728). The structure includes two Visual Studio C projects: 'disk_rw' and 'kernel_exec'. - 'disk_rw/main.c' demonstrates exploitation of CVE-2021-31727, where a non-privileged user can open a handle to the device '\\.\ZemanaAntiMalware' and use IOCTLs 0x80002014 (read) and 0x80002018 (write) to perform unrestricted disk sector read/write operations. The PoC reads the MBR, increments the disk ID, and writes it back, showing arbitrary disk modification capability. - 'kernel_exec/main.c' demonstrates exploitation of CVE-2021-31728, where a non-privileged user can allocate executable kernel memory, install a hook, and trigger execution of arbitrary code in ring 0 via the same device and IOCTLs. The PoC attempts to escalate privileges by executing shellcode in kernel context and then launching a SYSTEM-level command shell. Both exploits require local access and interact directly with the vulnerable driver via the device path '\\.\ZemanaAntiMalware'. The repository is well-structured for research and demonstration purposes, with clear separation of exploits for each CVE and supporting documentation in markdown files. No network endpoints are present; all exploitation is local and targets the Windows kernel via the driver interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.