CVE-2019-6493
Summary
| CVE | CVE-2019-6493 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-11 20:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user defined bytes and size when IOCTL 0x9C401CC0 is called. This kernel pointer can be leaked if the kernel pool becomes a "big" pool. |
Risk And Classification
Problem Types: CWE-401
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Iobit | Smart Defrag | 6 | All | All | All |
| Application | Iobit | Smart Defrag | 6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Best Free Disk Defrag Software - Smart Defrag by IObit | MISC | www.iobit.com | Product, Vendor Advisory |
| DownWithUp's Github Website | MISC | downwithup.github.io | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.