CVE-2017-16237 describes an Arbitrary Write vulnerability in the VIAGLT64.SYS driver of Vir.IT eXplorer Anti-Virus versions prior to 8.5.42, stemming from insufficient input validation for IOCtl 0x8273007C. This vulnerability carries a CVSS v3 score of 7.8 (High), indicating that a local attacker with low privileges could achieve high impact on confidentiality, integrity, and availability with low attack complexity. While not listed on the KEV catalog, an ExploitDB entry (EDB-43109) exists demonstrating local privilege escalation, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.5.42CPE matchmatch criteria | cpe:2.3:a:tgsoft:vir.it_explorer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.