VulnerabilityModified
CVE-2018-10828
ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section.
MEDIUM 5.5EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section. ApMsgFwd.exe uses the data written to this section as arguments to functions. This causes a denial of service condition when invalid pointers are written to the mapped section. This driver has been used with Dell, ThinkPad, and VAIO devices.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- alps/pointing-device driver
- Source
- cve@mitre.org
References
- http://support.lenovo.com/us/en/solutions/LEN-25654
- https://github.com/SouhailHammou/Exploits/blob/master/CVE-2018-10828/apmsgfwd_exploit_dos.cThird Party Advisory
- https://www.exploit-db.com/exploits/44610/Third Party Advisory, VDB Entry
- http://support.lenovo.com/us/en/solutions/LEN-25654
- https://github.com/SouhailHammou/Exploits/blob/master/CVE-2018-10828/apmsgfwd_exploit_dos.cThird Party Advisory
- https://www.exploit-db.com/exploits/44610/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.