Denial of Service Vulnerability in Malwarebytes Premium Driver
CVE-2018-5270

7.8HIGH

Key Information:

Vendor
CVE Published:
8 January 2018

What is CVE-2018-5270?

In Malwarebytes Premium version 3.3.1.2183, a vulnerability exists within the driver file FARFLT.SYS that allows local users to induce a denial of service by leveraging improper input validation on IOCtl 0x9c40e010. This could lead to system crashes or other undefined impacts. The vendor has stated that they were unable to replicate the issue across any versions of Windows, both 32-bit and 64-bit.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.