CVE-2018-3971
CVE-2018-3971
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.3EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
25 Oct 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Talos · SophosWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →