← Vulnerability feed

Vulnerability record · CVE-2013-3947 · published 24 April 2018

CVE-2013-3947: Ahnlab v3 internet security memory buffer overflow vulnerability

Ahnlab · V3 Internet Security

Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IOCTL call.

7.8 CVSS 3.0 High EPSS 0.48% · top 61.1% CWE-119 · Memory buffer overflowCWE-264 · Permissions and access controls
7.8CVSS 3.0 base score, v2 7.2
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IOCTL call.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/54465 Permissions RequiredThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/90626 Third Party AdvisoryVDB Entry
http://secunia.com/advisories/54465 Permissions RequiredThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/90626 Third Party AdvisoryVDB Entry

Track CVE-2013-3947 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%4.3CVE-2012-1459TAR parser malware detection bypass in multiple antivirus productsThe TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next en…EPSS 100%analysed4.3CVE-2012-1462ZIP parser in multiple antivirus products allows malware detection bypassThe ZIP file parser in numerous antivirus and endpoint protection products mishandles a ZIP archive containing an invalid data block at the beginning…EPSS 98%analysed4.3CVE-2012-1463Multiple antivirus ELF parsers bypassed via modified endianness fieldThe ELF file parser in a dozen antivirus products (AhnLab V3, Bitdefender, Quick Heal, Command, Comodo, eSafe, F-Prot, F-Secure, McAfee, Norman, nPro…EPSS 94%analysed4.3CVE-2012-1443RAR parser malware detection bypass in multiple antivirus enginesThe RAR file parser in dozens of antivirus products fails to correctly handle a RAR archive whose contents begin with an MZ character sequence, allow…EPSS 100%analysed4.3CVE-2012-1433Multiple antivirus EXE parsers allow malware detection bypassThe EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivi…EPSS 94%analysed4.3CVE-2012-1434Malware scanners bypassed by crafted EXE parser inputThe EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, Ikarus Virus Utilities T3 Command Line Scanner…EPSS 60%analysed

Source: NIST National Vulnerability Database (record CVE-2013-3947), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.