SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0552

Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is…

HIGH 7.5EPSS 23.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 23.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
23.87% probability · 98th percentile
CISA KEV
Not listed
Affected
sophos/small business suite
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.