First published: Tue Apr 29 2008(Updated: )
Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboot with the product disabled) and possibly gain privileges via a zero value in a certain length field in the ObjectAttributes argument to the NtCreateKey hooked System Service Descriptor Table (SSDT) function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Anti-Virus for Sophos Central macOS | =7.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-1737 is considered high, as it can lead to a denial of service and potential privilege escalation.
To fix CVE-2008-1737, upgrade Sophos Anti-Virus to a version beyond 7.0.5 where the vulnerability has been patched.
CVE-2008-1737 affects users of Sophos Anti-Virus versions 7.0.5 and other 7.x versions with Runtime Behavioural Analysis enabled.
CVE-2008-1737 is a local denial of service vulnerability that may also allow privilege escalation.
CVE-2008-1737 impacts the Runtime Behavioural Analysis feature of Sophos Anti-Virus.