VYPR
Unrated severityNVD Advisory· Published May 10, 2018· Updated Sep 17, 2024

CVE-2018-10977

CVE-2018-10977

Description

In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x002220E4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The 2345 Security Guard driver (2345BdPcSafe.sys, x64) fails to validate IOCTL 0x002220E4 input, enabling local users to trigger a denial of service (BSOD) via crafted input.

Vulnerability

The 2345 Security Guard version 3.7 driver 2345BdPcSafe.sys (x64) contains an input validation flaw in its handling of IOCTL 0x002220E4. The driver does not validate input values passed via this IOCTL, allowing a local user to trigger a Blue Screen of Death (BSOD) or cause other unspecified impacts. The vulnerability is described in a proof-of-concept (PoC) repository [1].

Exploitation

An attacker must have local access to the system and the ability to send IOCTL requests to the driver. The PoC demonstrates sending a crafted IOCTL 0x002220E4 with invalid input data, which causes the driver to fail and resulting in a BSOD. No additional privileges beyond local user access are required [1].

Impact

Successful exploitation results in a denial of service (BSOD) on the target system. The description also notes the possibility of unspecified other impacts, though the primary consequence documented is system crash [1]. The attacker does not gain elevated privileges or code execution based on the available information.

Mitigation

No official fix or patch has been disclosed in the available references. Users of 2345 Security Guard 3.7 should consider disabling or uninstalling the software until a patched version is released. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.