CVE-2019-6492
Last modified
CVE-2019-6492 is a vulnerability of currently unknown severity. SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user defined bytes and size when IOCTL 0x9C401CC4 is called. This kernel pointer can be leaked if the kernel pool becomes a "big" pool.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user defined bytes and size when IOCTL 0x9C401CC4 is called. This kernel pointer can be leaked if the kernel pool becomes a "big" pool.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iobit | Smart Defrag | 6.0 |
References
- https://downwithup.github.io/CVEPosts.htmlExploit, Third Party Advisory
- https://downwithup.github.io/CVEPosts.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6492?
How severe is CVE-2019-6492?
How do I fix CVE-2019-6492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6485Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 befor…
- CVE-2019-6486Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 a…
- CVE-2019-6487TP-Link WDR Series devices through firmware v3 (such as TL-W…
- CVE-2019-6488The string component in the GNU C Library (aka glibc or libc…
- CVE-2019-6489Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices bef…
- CVE-2019-6491RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Inject…
- CVE-2019-6493SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never fr…
- CVE-2019-6494IMFForceDelete.sys in IObit Malware Fighter 6.2 allows a low…
- CVE-2019-6496The ThreadX-based firmware on Marvell Avastar Wi-Fi devices,…
- CVE-2019-6497Hotels_Server through 2018-11-05 has SQL Injection via the c…
- CVE-2019-6498GattLib 0.2 has a stack-based buffer over-read in gattlib_co…
- CVE-2019-6499Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains …
Are you affected by CVE-2019-6492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
