SB2018121822 - Denial of service in Sysmon
Published: December 18, 2018
Security Bulletin ID
SB2018121822
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: N/A)
The vulnerability allows a remote attacker to cause DoS condition.The weakness exists due to Sysmon's driver (SysmonDrv.sys) consumes new area in Nonpaged pool memory every time configuration reloads, but driver does not free old area in Nonpaged pool memory. A remote attacker can trigger memory leak and cause the service to crash.
Remediation
Install update from vendor's website.