CVE-2014-1213: Medium severity Sophos Scanning Engine vulnerability
Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protection, cause a denial of service (resource consumption, CPU consumption, and eventual crash) or spoof "ready for update" messages by performing certain operations on mutexes or events including (1) DataUpdateRequest, (2) MmfMutexSAV-, (3) MmfMutexSAV-Info, (4) ReadyForUpdateSAV-, (5) ReadyForUpdateSAV-Info, (6) SAV-, (7) SAV-Info, (8) StateChange, (9) SuspendedSAV-, (10) SuspendedSAV-Info, (11) UpdateComplete, (12) UpdateMutex, (13) UpdateRequest, or (14) SophosALMonSessionInstance, as demonstrated by triggering a ReadyForUpdateSAV event and modifying the UpdateComplete, UpdateMutex, and UpdateRequest objects.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sophos Anti-Virus engine (SAVi)to a version that resolves this vulnerability.Fixed in 3.50.1 - Upgrade
Upgrade
VDL 4.97G 9.7.xto a version that resolves this vulnerability.Fixed in 9.7.9 - Upgrade
Upgrade
VDL 4.97G 10.0.xto a version that resolves this vulnerability.Fixed in 10.0.11 - Upgrade
Upgrade
VDL 4.97G 10.3.xto a version that resolves this vulnerability.Fixed in 10.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1213?
CVE-2014-1213 is considered a medium severity vulnerability that can lead to a denial of service.
How do I fix CVE-2014-1213?
To fix CVE-2014-1213, upgrade your Sophos Anti-Virus software to version 10.0.11 or later.
Who is affected by CVE-2014-1213?
CVE-2014-1213 affects users of Sophos Anti-Virus engine versions before 3.50.1 and specific versions of Sophos Anti-Virus 10.0.11 and earlier.
What type of attack does CVE-2014-1213 allow?
CVE-2014-1213 allows local users to bypass anti-virus protection and potentially cause a denial of service.
Is there a patch available for CVE-2014-1213?
Yes, the vulnerability is mitigated by applying the appropriate software update to Sophos Anti-Virus.