CVE-2018-20404

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
26/12/2018
Last modified:
14/02/2019

Description

ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (uncontrollable) address, resulting in an eternal hang or a BSoD.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:viatech:epia-e900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:viatech:epia-e900:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools