PT-2020-20147 · Trend Micro · Ossec-Hids

·

CVE-2020-8447

·

Published

2020-01-30

·

Updated

2022-09-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OSSEC-HIDS versions 2.7 through 3.5.0
Description The server component responsible for log analysis, ossec-analysisd, is vulnerable to a use-after-free during processing of syscheck formatted msgs. These messages are received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted.
Recommendations For OSSEC-HIDS versions 2.7 through 3.5.0, consider disabling the ossec-analysisd component temporarily until a patch is available to prevent potential exploitation. Restrict access to the ossec-remoted component to minimize the risk of receiving malicious syscheck formatted msgs.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8447

Affected Products

Ossec-Hids