CVE-2018-5278: Input Validation
DISPUTED In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit)."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5278?
CVE-2018-5278 has been reported as a potential denial of service vulnerability, though its severity level has been disputed.
How do I fix CVE-2018-5278?
To mitigate CVE-2018-5278, ensure you are using the latest version of Malwarebytes Premium, as updates may address this vulnerability.
What impact does CVE-2018-5278 have on affected systems?
CVE-2018-5278 can result in a denial of service condition, potentially causing a Blue Screen of Death (BSOD) in affected systems.
What versions are affected by CVE-2018-5278?
CVE-2018-5278 specifically affects Malwarebytes Premium version 3.3.1.2183.
Is CVE-2018-5278 being actively exploited?
Currently, there are no reports indicating active exploitation of CVE-2018-5278 in the wild.