CVE-2018-6471: Input Validation
Published Jan 31, 2018
·Updated
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402078.
Affected Software
1 affected component
SUPERAntiSpyware SUPERAntiSpyware=6.0.1254
Event History
Jan 31, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6471?
CVE-2018-6471 has a medium severity rating due to its potential for causing a denial of service.
2
How do I fix CVE-2018-6471?
To mitigate CVE-2018-6471, upgrade to the latest version of SUPERAntiSpyware that addresses this vulnerability.
3
Who is affected by CVE-2018-6471?
Users of SUPERAntiSpyware Professional Trial version 6.0.1254 are specifically affected by CVE-2018-6471.
4
What impact can CVE-2018-6471 have?
CVE-2018-6471 can lead to a denial of service, potentially crashing the system with a blue screen of death.
5
Is CVE-2018-6471 exploitable remotely?
CVE-2018-6471 is not remotely exploitable; it requires local access to the machine.