First published: Wed Sep 13 2017(Updated: )
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos HitmanPro | <=3.7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6008 has a critical severity rating as it allows local users to escalate privileges.
To fix CVE-2017-6008, update to Sophos HitmanPro version 3.7.20 or later.
CVE-2017-6008 affects users of Sophos HitmanPro versions prior to 3.7.20.
CVE-2017-6008 is a kernel pool overflow vulnerability found in the hitmanpro37.sys driver.
CVE-2017-6008 requires local access to be exploited, as it involves a malformed IOCTL call.