CVE-2018-3989: Medium severity wibukey vulnerability
An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in kernel memory disclosure. An attacker can send an IRP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3989?
CVE-2018-3989 is a kernel memory disclosure vulnerability in WIBU-SYSTEMS WibuKey.sys Version 6.40.
What is the severity of CVE-2018-3989?
The severity of CVE-2018-3989 is medium, with a severity value of 5.5.
How does CVE-2018-3989 work?
By sending a specially crafted IRP request, an attacker can cause the driver to return uninitialized memory, resulting in kernel memory disclosure.
How can CVE-2018-3989 be exploited?
CVE-2018-3989 can be exploited by an attacker sending a malicious IRP request to the vulnerable driver.
Is there a fix available for CVE-2018-3989?
Yes, a fix is available for CVE-2018-3989. It is recommended to update to a patched version of WIBU-SYSTEMS WibuKey.sys.