CVE-2018-16713: Buffer Overflow
IObit Advanced SystemCare, which includes Monitorwin10x64.sys or Monitorwin7x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16713?
CVE-2018-16713 is a vulnerability in IObit Advanced SystemCare that allows a user to execute arbitrary code.
How does CVE-2018-16713 work?
CVE-2018-16713 allows a user to send a specific IOCTL with a user-defined buffer, which can lead to the execution of arbitrary code.
What version of IObit Advanced SystemCare is affected by CVE-2018-16713?
IObit Advanced SystemCare version 1.2.0.5 (and possibly earlier versions) is affected by CVE-2018-16713.
What is the severity of CVE-2018-16713?
CVE-2018-16713 has a severity rating of 6.5 (Medium).
How can I fix CVE-2018-16713?
To fix CVE-2018-16713, update IObit Advanced SystemCare to a version higher than 1.2.0.5.