VDB
CVE-2018-5410
CVE-2018-5410
PUBLISHED
CVSS 7.800000190734863 HIGH
Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a device handle to the system driver and send arbitrary input that will trigger the vulnerability. This vulnerability was introduced in the 1.0.0.5000 version update.
EPSS 0.98% · 77.2th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.98%
77.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dokan-dev | dokany | 1.0.0.5000 |
| Dokan | Open Source File System | 1.0.0.5000, 1.2.0.1000 |
Timeline
- Jan 7, 2019 CVE Published
- Jan 14, 2019 PoC Published
- Jan 14, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
References
- VU#741315 third-party-advisory
- 46155 exploit
- https://cwe.mitre.org/data/definitions/121.html url
- https://github.com/dokan-dev/dokany/releases/tag/v1.2.1.1000 url
- 106274 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2018-5410 advisory
- https://kb.cert.org/vuls/id/741315 url
- https://www.exploit-db.com/exploits/46155 url