CVE-2018-5085: Input Validation
Published Jan 3, 2018
·Updated
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002124.
Affected Software
1 affected component
K7Computing Antivirus=15.1.0306
Event History
Jan 3, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5085?
CVE-2018-5085 has been classified as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2018-5085?
To mitigate CVE-2018-5085, it is recommended to update K7 AntiVirus to a version that addresses this issue.
3
Who is affected by CVE-2018-5085?
CVE-2018-5085 affects users of K7 AntiVirus version 15.1.0306.
4
What types of attacks can be executed with CVE-2018-5085?
CVE-2018-5085 can be exploited to cause a denial of service, specifically resulting in a blue screen of death (BSOD).
5
Is CVE-2018-5085 remotely exploitable?
CVE-2018-5085 is not remotely exploitable as it requires local access to the system to trigger the vulnerability.