← Vulnerability feed

Vulnerability record · CVE-2018-18026 · published 19 October 2018

CVE-2018-18026: Iobit malware fighter out-of-bounds write vulnerability

Iobit · Malware Fighter

IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.

7.8 CVSS 3.0 High EPSS 0.79% · top 45.4% CWE-787 · Out-of-bounds write
7.8CVSS 3.0 base score, v2 4.6
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-18026 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2016-20059Iobit malware fighter unquoted search path vulnerabilityIObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers …EPSS 0.18%7.8CVE-2023-1646Iobit malware fighter stack-based buffer overflow vulnerabilityA vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x…EPSS 0.37%7.8CVE-2020-23864Iobit malware fighter vulnerabilityAn issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the Windo…EPSS 0.51%7.8CVE-2018-19084Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E05C with a size larger …EPSS 0.60%7.8CVE-2018-19085Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E048 with a size larger …EPSS 0.60%7.8CVE-2018-19086Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E040 with a size larger …EPSS 0.60%7.8CVE-2018-19087Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E044 with a size larger …EPSS 0.60%7.8CVE-2018-18714Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This c…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2018-18026), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.