CVE-2018-6851: Buffer Overflow
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206040. By crafting an input buffer we can control the execution path to the point where the constant DWORD 0 will be written to a user-controlled address. We can take advantage of this condition to zero-out the pointer to the security descriptor in the object header of a privileged process or modify the security descriptor itself and run code in the context of a process running as SYSTEM.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6851?
CVE-2018-6851 has been classified as a medium severity vulnerability due to its local privilege escalation potential.
How do I fix CVE-2018-6851?
To remediate CVE-2018-6851, upgrade to SafeGuard Enterprise 8.00.5, SafeGuard Easy 7.00.3, or SafeGuard LAN Crypt 3.95.2 or later.
What are the affected versions in CVE-2018-6851?
CVE-2018-6851 affects Sophos SafeGuard Enterprise versions before 8.00.5, SafeGuard Easy versions before 7.00.3, and SafeGuard LAN Crypt versions before 3.95.2.
Is CVE-2018-6851 exploitable remotely?
CVE-2018-6851 is not remotely exploitable as it requires local access to the system.
What type of vulnerability is CVE-2018-6851?
CVE-2018-6851 is categorized as a Local Privilege Escalation vulnerability.