CVE-2008-5048
Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long inputs to the 0x00222494 IOCTL.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long inputs to the 0x00222494 IOCTL.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- isecsoft/anti-trojan elite
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32669Vendor Advisory
- http://www.ntinternals.org/ntiadv0802/ntiadv0802.html
- http://www.securityfocus.com/bid/32202
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46464
- http://secunia.com/advisories/32669Vendor Advisory
- http://www.ntinternals.org/ntiadv0802/ntiadv0802.html
- http://www.securityfocus.com/bid/32202
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46464
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.