CVE-2018-8998: Input Validation
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitorx86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-8998?
CVE-2018-8998 is a vulnerability in Advanced SystemCare Ultimate 11.0.1.58 that allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact.
What is the severity of CVE-2018-8998?
The severity of CVE-2018-8998 is high with a CVSS score of 7.8.
What software version is affected by CVE-2018-8998?
Advanced SystemCare Ultimate version 11.0.1.58 is affected by CVE-2018-8998.
How can a local user exploit CVE-2018-8998?
A local user can exploit CVE-2018-8998 by not validating input values from IOCtl 0x9c4060cc in the driver file (Monitor_x86.sys).
Is there a proof of concept available for CVE-2018-8998?
Yes, a proof of concept is available at this link: https://github.com/D0neMkj/POC_BSOD/tree/master/Advanced%20SystemCare%20Utimate/Monitor_win7_x86.sys-0x9c4060cc