CVE-2018-12096 describes a heap-based buffer over-read vulnerability in the liblnk library, specifically within the liblnk_data_string_get_utf8_string_size function, affecting versions up to 2018-04-19. This flaw, triggered by a crafted LNK file, could lead to information disclosure. Rated Medium severity (CVSS 5.5), it requires user interaction (UI:R) and local access (AV:L) for exploitation, with a high impact on confidentiality (C:H). Despite the vendor disputing the vulnerability, there is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20180419CPE matchmatch criteria | cpe:2.3:a:liblnk_project:liblnk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.