Denial of Service Vulnerability in Malwarebytes Premium Driver
CVE-2018-5274

7.8HIGH

Key Information:

Vendor
CVE Published:
8 January 2018

What is CVE-2018-5274?

In Malwarebytes Premium version 3.3.1.2183, a vulnerability exists within the driver file FARFLT.SYS, which can be exploited by local users. This exploitation can lead to a denial of service condition, potentially resulting in a Blue Screen of Death (BSOD) or other unspecified impacts. The issue arises due to the failure to properly validate input values from IOCtl 0x9C40E024, allowing attackers a pathway to disrupt system operations. Although the vendor has been unable to reproduce the issue across various Windows operating system versions, awareness and appropriate mitigation strategies should be implemented.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.