CVE-2018-18026
Last modified
CVE-2018-18026 is a vulnerability of currently unknown severity. IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iobit | Malware Fighter | <= 6.2 |
References
- https://downwithup.github.io/CVEPosts.htmlExploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/151849Third Party Advisory
- https://downwithup.github.io/CVEPosts.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18026?
How severe is CVE-2018-18026?
How do I fix CVE-2018-18026?
Are you affected by CVE-2018-18026?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
