CVE-2018-10828
Summary
| CVE | CVE-2018-10828 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-09 18:29:00 UTC |
| Updated | 2019-06-25 18:15:00 UTC |
| Description | An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section. ApMsgFwd.exe uses the data written to this section as arguments to functions. This causes a denial of service condition when invalid pointers are written to the mapped section. This driver has been used with Dell, ThinkPad, and VAIO devices. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alps | Pointing-device Driver | 10.1.101.207 | All | All | All |
| Application | Alps | Pointing-device Driver | 10.1.101.207 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alps Touchpad Driver Vulnerabilities - Lenovo Support US | CONFIRM | support.lenovo.com | |
| Dell Touchpad - 'ApMsgFwd.exe' Denial of Service - Windows dos Exploit | EXPLOIT-DB | www.exploit-db.com | Third Party Advisory, VDB Entry |
| Page not found · GitHub · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.