Buffer Overflow Vulnerability in IObit Malware Fighter by IObit
CVE-2018-18026
7.8HIGH
Key Information:
- Vendor
Iobit
- Status
- Vendor
- CVE Published:
- 19 October 2018
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2018-18026?
The IMFCameraProtect.sys component in IObit Malware Fighter 6.2 and earlier versions contains a vulnerability that allows attackers to exploit a stack-based buffer overflow. By using the DeviceIoControl function, an attacker can specify a user-defined size that could potentially overwrite critical return address values. This could result in unauthorized code execution or system crashes, thereby compromising the functionality of the software and leading to a denial of service.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.