CVE-2022-28874
Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- f-secure/atlant · f-secure/elements endpoint protection · f-secure/linux security · withsecure/cloud protection for salesforce · withsecure/elements collaboration protection
- Source
- cve-notifications-us@f-secure.com
References
- https://www.f-secure.com/en/home/support/security-advisoriesVendor Advisory
- https://www.withsecure.com/en/support/security-advisoriesThird Party Advisory
- https://www.f-secure.com/en/home/support/security-advisoriesVendor Advisory
- https://www.withsecure.com/en/support/security-advisoriesThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.