Denial of Service Vulnerability in Malwarebytes Premium by Malwarebytes
CVE-2018-5273

7.8HIGH

Key Information:

Vendor
CVE Published:
8 January 2018

What is CVE-2018-5273?

The vulnerability in Malwarebytes Premium 3.3.1.2183 arises from the inadequate validation of input values in the driver file FARFLT.SYS, specifically when handling IOCtl command 0x9c40e014. This security flaw may allow privilege escalation or cause a denial of service, potentially leading to a system crash (Blue Screen of Death). While the vendor has indicated difficulties in reproducing the issues across different Windows versions, the risk of local user exploitation remains serious, posing challenges to system stability and usability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.