rootpwn

medium · CVSS v3 3.3 · CVSS v4 4.8 · EPSS 0.00112

CVE-2026-94137

A local denial‑of‑service vulnerability exists in Hangzhou Shunwang Technology’s shzh 10.7.2.693 driver. The flaw is in the shdrv_x64.sys IR

Overview

A local denial‑of‑service vulnerability exists in Hangzhou Shunwang Technology’s shzh 10.7.2.693 driver. The flaw is in the shdrv_x64.sys IRP_MJ_DEVICE_CONTROL handler and can be triggered by manipulating the PID argument. Successful exploitation can cause the driver to crash, disrupting system stability.

Description

A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation of the argument PID leads to denial of service. The attack must be carried out locally.

Impact

The vulnerability impacts availability by allowing a local attacker to crash the shdrv_x64.sys driver, potentially leading to system instability or reboot. It does not directly affect confidentiality or integrity. Local users or administrators who can interact with the device interface are the primary impacted parties.

Remediation

Apply the vendor‑supplied patch or upgrade to a newer driver version that corrects the PID handling in shdrv_x64.sys. If a patch is unavailable, disable the shzh driver or restrict local access to the device interface via group policy or device guard. Monitor system logs for driver crash events and apply any relevant kernel updates that mitigate similar issues.

Risk context

The CVSS v3 score of 3.3 and EPSS of 0.00112 indicate a medium severity with low likelihood of exploitation. Defenders should assess local exposure and apply the patch promptly, but the risk is moderate and manageable.

Affected products

  • Hangzhou Shunwang shzh 10.7.2.693
  • shdrv_x64.sys

Scores

Severity
medium
CVSS v2
1.7
CVSS v3
3.3
CVSS v4
4.8
EPSS
0.00112

denial-of-service local-privilege driver kernel availability hangzhou-shunwang shdrv_x64.sys

← All CVEs