CVE-2008-1737: Input Validation
Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboot with the product disabled) and possibly gain privileges via a zero value in a certain length field in the ObjectAttributes argument to the NtCreateKey hooked System Service Descriptor Table (SSDT) function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1737?
The severity of CVE-2008-1737 is considered high, as it can lead to a denial of service and potential privilege escalation.
How do I fix CVE-2008-1737?
To fix CVE-2008-1737, upgrade Sophos Anti-Virus to a version beyond 7.0.5 where the vulnerability has been patched.
Who is affected by CVE-2008-1737?
CVE-2008-1737 affects users of Sophos Anti-Virus versions 7.0.5 and other 7.x versions with Runtime Behavioural Analysis enabled.
What type of vulnerability is CVE-2008-1737?
CVE-2008-1737 is a local denial of service vulnerability that may also allow privilege escalation.
What component of Sophos Anti-Virus is impacted by CVE-2008-1737?
CVE-2008-1737 impacts the Runtime Behavioural Analysis feature of Sophos Anti-Virus.