Improper input validation in Microsoft Windows - #VU12286

 

Improper input validation in Microsoft Windows - #VU12286

Published: April 30, 2018 / Updated: May 1, 2018


Vulnerability identifier: #VU12286
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists due to an error in Microsoft Windows while parsing a specially crafted NTFS image. A local attacker can open a specially crafted NTFS image and cause the service to crash.

Affected software

Microsoft Windows

Remediation

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.


External References

Related Security Bulletins