CVE-2026-19193: Improper Access Controls in Jiangmin Antivirus
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability affects Jiangmin Antivirus version 21 and is located in the MessageNotifyCallback function of the kvcore.sys library, part of the Minifilter Port component. Improper access controls can be manipulated by a local attacker to potentially escalate privileges or perform unauthorized actions. The vulnerability has a CVSS 4.0 base score of 8.5, indicating high severity. Exploit code has been published, but there is no indication of widespread exploitation. The vendor has not issued any response or remediation guidance.
Potential Impact
A local attacker with limited privileges can exploit this vulnerability to bypass access controls, potentially leading to unauthorized actions or privilege escalation within the affected system. The high CVSS score reflects the significant impact on confidentiality, integrity, and availability if exploited.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should restrict local access to trusted personnel only and monitor for suspicious activity related to the vulnerable component. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-19193: Improper Access Controls in Jiangmin Antivirus
Description
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 8.5high
Affected software
Jiangmin
Antivirus
cpe:2.3:a:jiangmin:antivirus:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Jiangmin Antivirus version 21 and is located in the MessageNotifyCallback function of the kvcore.sys library, part of the Minifilter Port component. Improper access controls can be manipulated by a local attacker to potentially escalate privileges or perform unauthorized actions. The vulnerability has a CVSS 4.0 base score of 8.5, indicating high severity. Exploit code has been published, but there is no indication of widespread exploitation. The vendor has not issued any response or remediation guidance.
Potential Impact
A local attacker with limited privileges can exploit this vulnerability to bypass access controls, potentially leading to unauthorized actions or privilege escalation within the affected system. The high CVSS score reflects the significant impact on confidentiality, integrity, and availability if exploited.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should restrict local access to trusted personnel only and monitor for suspicious activity related to the vulnerable component. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-06T20:06:03.663Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a755e94bf8831d539bda9fd
Added to database: 08/07/2026, 04:27:00 UTC
Last enriched: 08/14/2026, 14:58:09 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.