#VU15803 Stack-based buffer overflow in IObit Malware Fighter - CVE-2018-18026
Published: November 12, 2018 / Updated: November 22, 2018
IObit Malware Fighter
IObit
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in IMFCameraProtect.sys driver. A local user can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses, trigger stack-based buffer overflow and execute arbitrary code on the target system with elevated privileges.