CVE-2018-5410 EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 1.6% (pctl 75)
Patch early
A public exploit exists.
Description
Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a device handle to the system driver and send arbitrary input that will trigger the vulnerability. This vulnerability was introduced in the 1.0.0.5000 version update.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.59% — more likely to be exploited than 75% of all CVEs |
| Weakness | CWE-121 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-01-07 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| dokan-dev | dokany |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Dokany 1.2.0.1000 - Stack-Based Buffer Overflow Privilege Escalation | 2019-01-14 |
References
- http://www.securityfocus.com/bid/106274
- https://cwe.mitre.org/data/definitions/121.html
- https://github.com/dokan-dev/dokany/releases/tag/v1.2.1.1000
- https://kb.cert.org/vuls/id/741315/
- https://www.exploit-db.com/exploits/46155/
- http://www.securityfocus.com/bid/106274
- https://cwe.mitre.org/data/definitions/121.html
- https://github.com/dokan-dev/dokany/releases/tag/v1.2.1.1000
- https://kb.cert.org/vuls/id/741315/
- https://www.exploit-db.com/exploits/46155/
→ the Explorer · watch your stack · NVD