CVE-2018-5718
Last modified
CVE-2018-5718 is a vulnerability of currently unknown severity. Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, SoftControl/SafenSoft Enterprise Suite before version 4.4.1 allows local users to cause a denial of service (BSOD) or modify kernel-mode memory via loading of a forged DLL into an user-mode process.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, SoftControl/SafenSoft Enterprise Suite before version 4.4.1 allows local users to cause a denial of service (BSOD) or modify kernel-mode memory via loading of a forged DLL into an user-mode process.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Safensoft | Softcontrol Enterprise Suite | < 4.4.1 |
| Safensoft | Softcontrol Syswatch | < 4.4.1 |
| Safensoft | Softcontrol Tpsecure | < 4.4.1 |
References
- http://www.safensoft.com/security.phtml?c=865Vendor Advisory
- http://www.safensoft.com/security.phtml?c=865Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5718?
How severe is CVE-2018-5718?
How do I fix CVE-2018-5718?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5712An issue was discovered in PHP before 5.6.33, 7.0.x before 7…
- CVE-2018-5713In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.…
- CVE-2018-5714In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.…
- CVE-2018-5715phprint.php in SugarCRM 3.5.1 has XSS via a parameter name i…
- CVE-2018-5716An issue was discovered in Reprise License Manager 11.0. Thi…8.1
- CVE-2018-5717Memory write mechanism in NCR S2 Dispenser controller before…
- CVE-2018-5720An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wi…
- CVE-2018-5721Stack-based buffer overflow in the ej_update_variables funct…8.8
- CVE-2018-5723MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded passwo…
- CVE-2018-5724MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated C…
- CVE-2018-5725MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated C…
- CVE-2018-5726MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers …
Are you affected by CVE-2018-5718?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
