SB2018102521 - Multiple vulnerabilities in Sophos HitmanPro.Alert



SB2018102521 - Multiple vulnerabilities in Sophos HitmanPro.Alert

Published: October 25, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018102521
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2018-3970)

The vulnerability allows a local authenticated user to gain access to sensitive information.

An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in kernel memory disclosure. An attacker can send an IRP request to trigger this vulnerability.


2) Write-what-where Condition (CVE-ID: CVE-2018-3971)

The vulnerability allows a local authenticated user to execute arbitrary code.

An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.


Remediation

Install update from vendor's website.