VYPR
Unrated severityNVD Advisory· Published Oct 25, 2018· Updated Sep 17, 2024

CVE-2018-3971

CVE-2018-3971

Description

An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.

Affected products

1
  • Range: Sophos HitmanPro.Alert - hmpalert.sys 3.7.6.744 - Windows 7 x86

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.