Kernel Memory Leak in IObit Smart Defrag Software
CVE-2019-6492

5.5MEDIUM

Key Information:

Vendor

Iobit

Vendor
CVE Published:
18 March 2019

What is CVE-2019-6492?

A vulnerability exists in IObit Smart Defrag 6 where the SmartDefragDriver.sys version 2.0 does not appropriately manage memory for a kernel pool. When the IOCTL call 0x9C401CC4 is executed, it fails to release an allocated executable kernel pool with user-defined size parameters. As a result, this oversight can lead to kernel pointer leaks if the kernel pool escalates to a considerably large size, potentially compromising system integrity and security.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.