CVE-2018-3971: Critical severity sophos hitmanpro.alert vulnerability
An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-3971.
What is the severity of CVE-2018-3971?
The severity of CVE-2018-3971 is critical, with a severity value of 7.8.
Which software is affected by CVE-2018-3971?
Sophos HitmanPro.Alert version 3.7.6.744 is affected by CVE-2018-3971.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-123.
Are there any references available for CVE-2018-3971?
Yes, there are references available for CVE-2018-3971. You can find them at the following links: [SecurityFocus](http://www.securityfocus.com/bid/105743) and [Talos Intelligence](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0636).