CVE-2019-19820: Kyrol Internet Security

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read primitive.

Affected products

  • Kyrol Internet Security: version 9.0.6.9 only

Published 2020-01-10. Last modified 2026-06-17.