PT-2020-20185 · Norman · Norman Malware Cleaner
Published
2020-02-03
·
Updated
2020-02-06
·
CVE-2020-8508
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Norman Malware Cleaner version 2.08.08
Description
The issue arises from the mishandling of function pointers passed between user and kernel mode in the nsak64.sys driver, allowing users to call arbitrary kernel functions.
Recommendations
For Norman Malware Cleaner version 2.08.08, consider disabling the nsak64.sys driver until a patch is available to prevent the potential for arbitrary kernel function calls.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Norman Malware Cleaner