#VU15802 Stack-based buffer overflow in IObit Malware Fighter - CVE-2018-18714

 

#VU15802 Stack-based buffer overflow in IObit Malware Fighter - CVE-2018-18714

Published: November 12, 2018 / Updated: November 22, 2018


Vulnerability identifier: #VU15802
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2018-18714
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: Public exploit is available
Vulnerable software:
IObit Malware Fighter
Software vendor:
IObit

Description

The vulnerability allows a local user to execute arbitrary code with elevated privileges.

The vulnerability exists due to a boundary error when an attacker uses IOCTL 0x8006E010 within RegFilter.sys. A local user can trigger stack-based buffer overflow and cause denial of service (DoS) or code execution with root privileges.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links