CVE-2017-6007: Buffer Overflow
Published Sep 13, 2017
·Updated
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to crash the OS via a malformed IOCTL call.
Affected Software
1 affected component
Sophos hitmanpro<=3.7.20
Event History
Sep 13, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-6007?
CVE-2017-6007 is categorized as a high severity vulnerability due to its potential to allow local users to crash the operating system.
2
How do I fix CVE-2017-6007?
To mitigate CVE-2017-6007, users should upgrade Sophos HitmanPro to version 3.7.20 or later.
3
What systems are affected by CVE-2017-6007?
CVE-2017-6007 affects Sophos HitmanPro versions prior to 3.7.20.
4
What is the impact of CVE-2017-6007?
The impact of CVE-2017-6007 includes the ability for local users to crash the operating system through a malformed IOCTL call.
5
Is CVE-2017-6007 exploitable remotely?
CVE-2017-6007 is not exploitable remotely as it requires local access to the system.