CVE-2004-0552
Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 23.87% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- sophos/small business suite
- Source
- cve@mitre.org
References
- http://www.idefense.com/application/poi/display?id=143&type=vulnerabilities
- http://www.seifried.org/security/advisories/kssa-005.htmlExploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17468
- http://www.idefense.com/application/poi/display?id=143&type=vulnerabilities
- http://www.seifried.org/security/advisories/kssa-005.htmlExploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17468
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.