CVE-2018-7250
Last modified
CVE-2018-7250 is a vulnerability of currently unknown severity. An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool data.. EPSS estimates a 3.03% chance of exploitation in the next 30 days.
Description
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool data.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 7 | All versions |
| Microsoft | Windows 8 | All versions |
| Microsoft | Windows 8.1 | All versions |
| Microsoft | Windows Vista | All versions |
| Tivo | Safedisc | All versions |
References
- https://github.com/Elvin9/SecDrvPoolLeak/blob/master/README.mdThird Party Advisory
- https://github.com/Elvin9/SecDrvPoolLeak/blob/master/README.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7250?
How severe is CVE-2018-7250?
How do I fix CVE-2018-7250?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7244An information disclosure vulnerability exists In Schneider …
- CVE-2018-7245An improper authorization vulnerability exists In Schneider …
- CVE-2018-7246A cleartext transmission of sensitive information vulnerabil…
- CVE-2018-7247An issue was discovered in pixHtmlViewer in prog/htmlviewer.…
- CVE-2018-7248An issue was discovered in Zoho ManageEngine ServiceDesk Plu…5.3
- CVE-2018-7249An issue was discovered in secdrv.sys as shipped in Microsof…
- CVE-2018-7251An issue was discovered in config/error.php in Anchor 0.12.3…
- CVE-2018-7253The ParseDsdiffHeaderConfig function of the cli/dsdiff.c fil…
- CVE-2018-7254The ParseCaffHeaderConfig function of the cli/caff.c file of…
- CVE-2018-7259The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320…
- CVE-2018-7260Cross-site scripting (XSS) vulnerability in db_central_colum…
- CVE-2018-7261There are multiple Persistent XSS vulnerabilities in Radiant…
Are you affected by CVE-2018-7250?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
