CVE-2017-6008: Buffer Overflow
Published Sep 13, 2017
·Updated
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.
Affected Software
1 affected component
Sophos hitmanpro<=3.7.20
Event History
Sep 13, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-6008?
CVE-2017-6008 has a critical severity rating as it allows local users to escalate privileges.
2
How do I fix CVE-2017-6008?
To fix CVE-2017-6008, update to Sophos HitmanPro version 3.7.20 or later.
3
Who is affected by CVE-2017-6008?
CVE-2017-6008 affects users of Sophos HitmanPro versions prior to 3.7.20.
4
What type of vulnerability is CVE-2017-6008?
CVE-2017-6008 is a kernel pool overflow vulnerability found in the hitmanpro37.sys driver.
5
Can CVE-2017-6008 be exploited remotely?
CVE-2017-6008 requires local access to be exploited, as it involves a malformed IOCTL call.