PT-2018-16351 · Sophos · Sophos Hitmanpro.Alert

Published

2018-10-25

·

Updated

2023-02-02

·

CVE-2018-3971

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos HitmanPro.Alert version 3.7.6.744
Description An arbitrary write issue exists in the 0x2222CC IOCTL handler functionality. A specially crafted IRP request can cause the driver to write data to an address controlled by an attacker, resulting in memory corruption. An attacker can send an IRP request to trigger this issue.
Recommendations For Sophos HitmanPro.Alert version 3.7.6.744, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2018-3971

Affected Products

Sophos Hitmanpro.Alert