VYPR
Unrated severityNVD Advisory· Published May 25, 2022· Updated Aug 3, 2024

Denial-of-Service (DoS) Vulnerability

CVE-2022-28875

Description

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aemobile component can crash the scanning engine. The exploit can be triggered remotely by an attacker.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial-of-service vulnerability in F-Secure Atlant and WithSecure products allows remote attackers to crash the scanning engine via the aemobile component.

Vulnerability

The vulnerability resides in the aemobile component of F-Secure Atlant and certain WithSecure products. When the scanning engine processes a specially crafted file or request targeting this component, it can cause a crash, leading to denial of service. The exact affected versions are not specified in the available references, but the advisory covers all F-Secure endpoint protection products for Windows and Mac [1] and WithSecure Atlant product [2].

Exploitation

An attacker can trigger this vulnerability remotely without authentication by sending a malicious file or network request that is scanned by the vulnerable aemobile component. No user interaction is required beyond the normal scanning process.

Impact

Successful exploitation results in a denial of service, crashing the scanning engine. This can prevent the security software from detecting threats, leaving the system unprotected until the engine is restarted.

Mitigation

F-Secure and WithSecure have likely released patches; however, the specific fixed version is not disclosed in the provided references. Users should consult the official security advisories [1][2] for updates and apply the latest product updates. If no patch is available, consider temporarily disabling the aemobile component if possible, but this is not recommended.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • F-Secure/All F-Secure & WithSecure endpoint protection products for Windows and Mac. F-Secure Linux Security (32-bit). F-Secure Linux Security (64-bit). F-Secure Atlant. WithSecure Cloud Protection for Salesforce & WithSecure Collaboration Protectionv5
    Range: All Version

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.