SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-22061

This issue allows attackers to arbitrarily write data to the device via IOCTL 0x9C402140.

HIGH 7.8EPSS 0.32%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

SUPERAntispyware v8.0.0.1050 was discovered to contain an issue in the component saskutil64.sys. This issue allows attackers to arbitrarily write data to the device via IOCTL 0x9C402140.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Affected
superantispyware/superantispyware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.