PT-2018-18002 · Armadito · Armadito

Souhail Hammou

·

Publicado

2018-02-21

·

Atualizado

2018-03-17

·

CVE-2018-7289

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Armadito version 0.12.7.2
Description An issue in the Armadito windows driver allows malware with filenames containing pure UTF-16 characters to bypass detection. The user-mode service fails to open the file for scanning after converting Unicode to ANSI, as characters that cannot be converted are replaced with '?' characters.
Recommendations For Armadito version 0.12.7.2, consider implementing a workaround to handle filenames with UTF-16 characters properly, such as manually checking for malware in files that fail to open for scanning, until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7289

Produtos afetados

Armadito