First published: Sun Mar 25 2018(Updated: )
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IOBit Advanced SystemCare Ultimate | =11.0.1.58 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8998 is a vulnerability in Advanced SystemCare Ultimate 11.0.1.58 that allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact.
The severity of CVE-2018-8998 is high with a CVSS score of 7.8.
Advanced SystemCare Ultimate version 11.0.1.58 is affected by CVE-2018-8998.
A local user can exploit CVE-2018-8998 by not validating input values from IOCtl 0x9c4060cc in the driver file (Monitor_x86.sys).
Yes, a proof of concept is available at this link: https://github.com/D0neMkj/POC_BSOD/tree/master/Advanced%20SystemCare%20Utimate/Monitor_win7_x86.sys-0x9c4060cc