CVE-2018-6522
Summary
| CVE | CVE-2018-6522 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-02 01:29:00 UTC |
| Updated | 2018-02-21 16:53:00 UTC |
| Description | In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKRgFtXp.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220408. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| nProtectAntivirus_POC/TKRgFtXp_0x220408 at master · ZhiyuanWang-Chengdu-Qihoo360/nProtectAntivirus_POC · GitHub |
MISC |
github.com |
Third Party Advisory |
| inca.co.kr/include_file/pdf_down/nProtect%20AVS%20V4%20Vulnerability%20R... |
CONFIRM |
inca.co.kr |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| INCA Internet | 2018-02-21 | Tom Lee | The reported vulnerability is fixed in version 4.0.0.39 of nPrtoect AVS.<br /> The fixed version(V4.0.0.39) can be downloaded through the link below.<br /> Please download the latest version of nProtect AVS. <br /> <br /> Download link : http://avsd.nprotect.net/avs40/setup/nProtectSetup_AVS40.exe |
There are currently no legacy QID mappings associated with this CVE.