Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18026

Опубликовано: 19 окт. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:iobit:malware_fighter:*:*:*:*:*:*:*:*
Версия до 6.2 (включая)

EPSS

Процентиль: 83%
0.02048
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.

EPSS

Процентиль: 83%
0.02048
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-787