CVE-2018-5080: Input Validation
Published Jan 3, 2018
·Updated
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020FC.
Affected Software
1 affected component
K7Computing Antivirus=15.1.0306
Event History
Jan 3, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5080?
CVE-2018-5080 is classified with a high severity due to its potential to cause a denial of service (BSOD).
2
How do I fix CVE-2018-5080?
To fix CVE-2018-5080, ensure that you update K7 AntiVirus to the latest version where the vulnerability is patched.
3
What impact does CVE-2018-5080 have on users?
CVE-2018-5080 allows local users to cause a denial of service, potentially leading to system crashes.
4
Which versions of K7 AntiVirus are affected by CVE-2018-5080?
K7 AntiVirus version 15.1.0306 is affected by CVE-2018-5080.
5
Is there a workaround for CVE-2018-5080 if I cannot update?
Currently, there is no known workaround for CVE-2018-5080 other than applying the necessary updates from K7 Computing.