An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by sending IOCTL 0x80002010 and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.
- https://www.exploit-db.com/exploits/43987/
- https://github.com/DISREL/Ring0VBA
- https://github.com/SouhailHammou/Exploits
- https://github.com/hfiref0x/KDU
- https://github.com/jakydibe/ZammOcide