First published: Tue Feb 05 2019(Updated: )
An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege escalation. An attacker can send an IRP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
=6.40 | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3990 is a pool corruption vulnerability in the WIBU-SYSTEMS WibuKey.sys driver that can be exploited to cause kernel memory corruption and potentially escalate privileges.
CVE-2018-3990 is considered critical with a severity score of 7.8.
WibuKey.sys Version 6.40 (Build 2400) is affected by CVE-2018-3990.
CVE-2018-3990 can be exploited by sending a specially crafted IRP request to trigger a buffer overflow.
No, Microsoft Windows is not vulnerable to CVE-2018-3990.
The CWE ID for CVE-2018-3990 is CWE-119.