CVE-2018-18026: Buffer Overflow
IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-18026.
What is the severity of CVE-2018-18026?
The severity of CVE-2018-18026 is high.
What is affected by CVE-2018-18026?
IOBit Malware Fighter versions up to and including 6.2 are affected by CVE-2018-18026.
How can an attacker exploit CVE-2018-18026?
An attacker can exploit CVE-2018-18026 by using DeviceIoControl to pass a user-specified size, which can lead to a stack-based buffer overflow and potentially overwrite return addresses.
Are there any fixes or patches available for CVE-2018-18026?
Please refer to the vendor's website or security advisories for available fixes or patches for CVE-2018-18026.