An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section. ApMsgFwd.exe uses the data written to this section as arguments to functions. This causes a denial of service condition when invalid pointers are written to the mapped section. This driver has been used with Dell, ThinkPad, and VAIO devices.
References
Link | Resource |
---|---|
http://support.lenovo.com/us/en/solutions/LEN-25654 | |
https://github.com/SouhailHammou/Exploits/blob/master/CVE-2018-10828/apmsgfwd_exploit_dos.c | Third Party Advisory |
https://www.exploit-db.com/exploits/44610/ | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2018-05-09 18:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-10828
Mitre link : CVE-2018-10828
CVE.ORG link : CVE-2018-10828
JSON object : View
Products Affected
alps
- pointing-device_driver
CWE
CWE-20
Improper Input Validation