Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-7441

Опубликовано: 13 сент. 2017
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0 might lead to kernel data leaks. Because the leak occurs at the driver level, an attacker can use this vulnerability to leak some critical information about the machine such as nt!ExpPoolQuotaCookie.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sophos:hitmanpro:*:*:*:*:*:*:*:*
Версия до 3.7.20 (включая)

EPSS

Процентиль: 9%
0.00032
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0 might lead to kernel data leaks. Because the leak occurs at the driver level, an attacker can use this vulnerability to leak some critical information about the machine such as nt!ExpPoolQuotaCookie.

EPSS

Процентиль: 9%
0.00032
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-119