CVE-2018-9151: Null Pointer Dereference
Published Mar 30, 2018
·Updated
A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.
Affected Software
1 affected component
KINGSOFT Internet Security 9 Plus=2010.06.23.247
Event History
Mar 30, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2018-9151.
2
What is the severity of CVE-2018-9151?
The severity of CVE-2018-9151 is medium.
3
What is the affected software for CVE-2018-9151?
The affected software for CVE-2018-9151 is KINGSOFT Internet Security 9 Plus version 2010.06.23.247.
4
How can local non-privileged users exploit CVE-2018-9151?
Local non-privileged users can exploit CVE-2018-9151 by sending IOCTL 0x80030030 requests to the kernel driver KWatch3.sys.
5
Is there a reference for more information about CVE-2018-9151?
Yes, you can find more information about CVE-2018-9151 at http://seclists.org/fulldisclosure/2018/Mar/78.