Vulnerability CVE-2018-5701


Published: 2018-01-31

Description:
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
System Shield 5.0.0.136 Privilege Escalation
Parvez Anwar
31.01.2018

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
IOLO -> System shield 

 References:
http://packetstormsecurity.com/files/146165/System-Shield-5.0.0.136-Privilege-Escalation.html
https://www.exploit-db.com/exploits/43929/
https://www.greyhathacker.net/?p=1006

Copyright 2024, cxsecurity.com

 

Back to Top