Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural...
Vulnerability Description
Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboot with the product disabled) and possibly gain privileges via a zero value in a certain length field in the ObjectAttributes argument to the NtCreateKey hooked System Service Descriptor Table (SSDT) function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-1737
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/29996
- http://www.securityfocus.com/bid/28743
- http://securityreason.com/securityalert/3838
- http://www.vupen.com/english/advisories/2008/1381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42083
- http://www.coresecurity.com/?action=item&id=2249
- http://www.sophos.com/support/knowledgebase/article/37810.html
- http://www.securityfocus.com/archive/1/491405/100/0/threaded
- http://securitytracker.com/id?1019945
More from sophos
View All →Affected Vendor
sophos
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.