ID:224 - Exploit for Stack-based buffer overflow in IObit Malware Fighter - CVE-2018-18026
Published: March 18, 2020
IObit Malware Fighter
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in IMFCameraProtect.sys driver. A local user can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses, trigger stack-based buffer overflow and execute arbitrary code on the target system with elevated privileges.