Description
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional privilege is granted to the attacker beyond what is already possessed to run MapDrv.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20666 | MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional privilege is granted to the attacker beyond what is already possessed to run MapDrv. |
References
History
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T20:12:36.388Z
Reserved: 2018-03-27T00:00:00.000Z
Link: CVE-2018-9063
No data.
Status : Modified
Published: 2018-05-04T17:29:00.770
Modified: 2024-11-21T04:14:53.817
Link: CVE-2018-9063
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD