Multiple Denial of Service Vulnerability
Description
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A denial-of-service vulnerability in the aerdl.dll unpacker handler of F-Secure and WithSecure endpoint protection products can cause a scanning engine crash.
Vulnerability
The vulnerability resides in the aerdl.dll unpacker handler function used by F-Secure and WithSecure endpoint protection products on Windows and Mac. When processing a specially crafted file, the handler crashes, leading to a denial of service. Affected versions include all F-Secure endpoint protection products for Windows and Mac, as well as corresponding WithSecure products. [1]
Exploitation
An attacker can exploit this vulnerability by providing a malicious file that triggers the crash in the aerdl.dll unpacker. No authentication or user interaction is required beyond the file being scanned by the affected product. The attacker does not need network access if the file is delivered via email, web download, or other means that the product scans.
Impact
Successful exploitation results in a denial of service (DoS) condition where the scanning engine crashes. This prevents the product from scanning files, potentially leaving the system unprotected until the engine is restarted. The crash does not lead to code execution or privilege escalation.
Mitigation
F-Secure and WithSecure have released updates to address this vulnerability. Users should update their endpoint protection products to the latest versions. The advisory [1] lists the CVE with a date of 2022-09-30, indicating a fix was available by that date. No workarounds are documented; updating is the recommended mitigation.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- F-Secure and WithSecure/All F-Secure and WithSecure Endpoint Protection products for Windows & Mac F-Secure Linux Security (32-bit) F-Secure Linux Security (64-bit) F-Secure Atlant F-Secure Internet Gatekeeperv5Range: All Version
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.