PT-2020-20185 · Norman · Norman Malware Cleaner

Published

2020-02-03

·

Updated

2020-02-06

·

CVE-2020-8508

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Norman Malware Cleaner version 2.08.08
Description The issue arises from the mishandling of function pointers passed between user and kernel mode in the nsak64.sys driver, allowing users to call arbitrary kernel functions.
Recommendations For Norman Malware Cleaner version 2.08.08, consider disabling the nsak64.sys driver until a patch is available to prevent the potential for arbitrary kernel function calls.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8508

Affected Products

Norman Malware Cleaner