Input validation error in Antivirus One - CVE-2024-45335

 

Input validation error in Antivirus One - CVE-2024-45335

Published: September 5, 2024


Vulnerability identifier: #VU96901
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45335
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass malware detection.

The vulnerability exists due to insufficient validation of extended file attributes when scanning files. A remote attacker can evade malware detection using specially crafted attributes for the malicious binary file.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

Antivirus One

How to mitigate CVE-2024-45335

Install updates from vendor's website.

Antivirus One - update to 3.10.6

External References

Related Security Bulletins