CVE-2018-9002: Input Validation
Published Mar 25, 2018
·Updated
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitorwin7x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.
Affected Software
1 affected component
IObit Advanced SystemCare Ultimate=11.0.1.58
Event History
Mar 25, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-9002.
2
What is the severity of CVE-2018-9002?
The severity of CVE-2018-9002 is high with a CVSS score of 7.8.
3
How does the vulnerability in Advanced SystemCare Ultimate 11.0.1.58 occur?
The vulnerability occurs due to the driver file (Monitor_win7_x64.sys) not validating input values from IOCtl 0x9c4060cc.
4
What are the possible impacts of CVE-2018-9002?
The vulnerability can cause a denial of service (BSOD) or have unspecified other impacts.
5
Is there a fix available for CVE-2018-9002?
Yes, IOBit Advanced SystemCare Ultimate should release a patch or update to fix this vulnerability.