PT-2017-6763 · Blue Coat · Blue Coat Malware Analysis Appliance+1
Published
2017-09-11
·
Updated
2018-10-03
·
CVE-2015-4523
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Blue Coat Malware Analysis Appliance (MAA) versions prior to 4.2.5
Malware Analyzer G2 (affected versions not specified)
Description
The issue allows remote attackers to bypass a virtual machine protection mechanism. This can lead to writing to arbitrary files, causing a denial of service (resulting in a host reboot or reset to factory defaults), or executing arbitrary code. The attack vectors are related to saving files during analysis.
Recommendations
For Blue Coat Malware Analysis Appliance (MAA) versions prior to 4.2.5, update to version 4.2.5 or later to resolve the issue.
For Malware Analyzer G2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blue Coat Malware Analysis Appliance
Malware Analyzer G2