CVE-2018-6784: Input Validation
Published Feb 6, 2018
·Updated
In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A00824C.
Affected Software
1 affected component
Jiangmin Antivirus=16.0.0.100
Event History
Feb 6, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6784?
CVE-2018-6784 has a medium severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2018-6784?
To remediate CVE-2018-6784, update to the latest version of Jiangmin Antivirus that addresses this vulnerability.
3
Who is affected by CVE-2018-6784?
CVE-2018-6784 affects local users of Jiangmin Antivirus version 16.0.0.100.
4
What type of vulnerability is CVE-2018-6784?
CVE-2018-6784 is a denial of service vulnerability that arises from improper input validation.
5
Can CVE-2018-6784 be exploited remotely?
CVE-2018-6784 requires local access to exploit, so it cannot be exploited remotely.