CVE-2018-9042: Input Validation
Published Mar 27, 2018
·Updated
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitorwin10x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.
Affected Software
1 affected component
IObit Advanced SystemCare Ultimate=11.0.1.58
Event History
Mar 27, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue in Advanced SystemCare Ultimate 11.0.1.58?
The vulnerability ID is CVE-2018-9042.
2
What is the severity level of CVE-2018-9042?
The severity level of CVE-2018-9042 is high, with a CVSS score of 7.8.
3
What is the impact of CVE-2018-9042?
The impact of CVE-2018-9042 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact.
4
How does CVE-2018-9042 affect Advanced SystemCare Ultimate 11.0.1.58?
CVE-2018-9042 affects Advanced SystemCare Ultimate 11.0.1.58 due to the driver file (Monitor_win10_x64.sys) not validating input values from IOCtl 0x9c402000.
5
Is there a fix available for CVE-2018-9042?
Please refer to the vendor for a fix or mitigation steps for CVE-2018-9042.