PT-2019-18116 · Iobit · Iobit Smart Defrag

Published

2019-04-11

·

Updated

2020-08-24

·

CVE-2019-6493

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IObit Smart Defrag version 6
Description The issue concerns the SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6, where an executable kernel pool allocated with user-defined bytes and size is not freed when a specific IOCTL (0x9C401CC0) is called. This can lead to a kernel pointer leak if the kernel pool becomes a "big" pool.
Recommendations For IObit Smart Defrag version 6, consider disabling the IOCTL 0x9C401CC0 call as a temporary workaround until a patch is available. Restrict access to the SmartDefragDriver.sys module to minimize the risk of exploitation. Avoid using the IOCTL 0x9C401CC0 in the affected driver until the issue is resolved.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6493

Affected Products

Iobit Smart Defrag