CVE-2018-12098 describes a heap-based buffer over-read vulnerability in the liblnk_data_block_read function within liblnk, affecting versions through 2018-04-19. This medium-severity vulnerability (CVSS 5.5) can lead to information disclosure when a user opens a specially crafted LNK file, requiring user interaction and local access to the system. Despite the potential for information disclosure, the vendor has disputed this vulnerability, and there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20180419CPE matchmatch criteria | cpe:2.3:a:liblnk_project:liblnk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.