CVE-2018-5272: Input Validation
DISPUTED In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e004. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit)."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5272?
CVE-2018-5272 has a severity rating that may indicate a potential denial of service vulnerability in Malwarebytes Premium 3.3.1.2183.
How do I fix CVE-2018-5272?
To address CVE-2018-5272, update Malwarebytes to the latest version that includes patches for this vulnerability.
What impact can CVE-2018-5272 have on my system?
CVE-2018-5272 can cause a denial of service leading to a Blue Screen of Death (BSOD) if exploited.
Which software versions are affected by CVE-2018-5272?
CVE-2018-5272 specifically affects Malwarebytes Premium version 3.3.1.2183.
Is CVE-2018-5272 being actively exploited?
There are currently no confirmed reports of active exploitation of CVE-2018-5272.