CVE-2018-9000: Input Validation
Published Mar 25, 2018
·Updated
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitorx86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.
Affected Software
1 affected component
IObit Advanced SystemCare Ultimate=11.0.1.58
Event History
Mar 25, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-9000?
CVE-2018-9000 is a vulnerability in Advanced SystemCare Ultimate 11.0.1.58 that allows local users to cause a denial of service (BSOD) or have unspecified other impact due to not validating input values from IOCtl 0x9c402004.
2
What is the severity of CVE-2018-9000?
The severity of CVE-2018-9000 is high with a CVSS score of 7.8.
3
How does CVE-2018-9000 affect Advanced SystemCare Ultimate?
CVE-2018-9000 affects Advanced SystemCare Ultimate 11.0.1.58.
4
What is the CWE ID for CVE-2018-9000?
The CWE ID for CVE-2018-9000 is 20.
5
How can I fix CVE-2018-9000?
To fix CVE-2018-9000, update Advanced SystemCare Ultimate to a version that has addressed the vulnerability.