Vulnerabilities > CVE-2018-9151 - NULL Pointer Dereference vulnerability in Kingsoft Internet Security 9 Plus 2010.06.23.247

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
kingsoft
CWE-476

Summary

A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.

Vulnerable Configurations

Part Description Count
Application
Kingsoft
1

Common Weakness Enumeration (CWE)