First published: Wed Sep 13 2017(Updated: )
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to crash the OS via a malformed IOCTL call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Hitmanpro | <=3.7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6007 is categorized as a high severity vulnerability due to its potential to allow local users to crash the operating system.
To mitigate CVE-2017-6007, users should upgrade Sophos HitmanPro to version 3.7.20 or later.
CVE-2017-6007 affects Sophos HitmanPro versions prior to 3.7.20.
The impact of CVE-2017-6007 includes the ability for local users to crash the operating system through a malformed IOCTL call.
CVE-2017-6007 is not exploitable remotely as it requires local access to the system.