CVE-2018-9151: Kingsoft Internet Security 9 Plus

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.

Affected products

  • Kingsoft Internet Security 9 Plus: version 2010.06.23.247 only

Published 2018-03-30. Last modified 2026-06-17.