CVE-2018-18026: Iobit Malware Fighter

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.

Affected products

  • Iobit Malware Fighter: up to and including 6.2

Published 2018-10-19. Last modified 2026-06-17.