SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10828

ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section.

MEDIUM 5.5EPSS 1.40%

Does this matter?

Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section. ApMsgFwd.exe uses the data written to this section as arguments to functions. This causes a denial of service condition when invalid pointers are written to the mapped section. This driver has been used with Dell, ThinkPad, and VAIO devices.

CVSS 3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
1.40% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
alps/pointing-device driver
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.