Vulnerability Description
DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user defined buffer size. If the size of the buffer is less than 512 bytes, then the driver will overwrite the next pool header if there is one next to the user buffer's pool.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Driveagent | Driveagent | 2.2015.7.14 |
Related Weaknesses (CWE)
References
- https://blog.securityevaluators.com/vulnerabilities-in-terramaster-tos-3-1-03-fbBroken Link
- https://downwithup.github.io/CVEPosts.htmlThird Party Advisory
- https://blog.securityevaluators.com/vulnerabilities-in-terramaster-tos-3-1-03-fbBroken Link
FAQ
What is CVE-2018-19523?
CVE-2018-19523 is a vulnerability with a CVSS score of 5.5 (MEDIUM). DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user defined buffer size. If the size of the buffer is less than 512 bytes, then the ...
How severe is CVE-2018-19523?
CVE-2018-19523 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19523?
Check the references section above for vendor advisories and patch information. Affected products include: Driveagent Driveagent.