CVE-2018-7289: Low severity Teclib-edition Armadito Antivirus vulnerability
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
armadito-windows-driver/src/communication.cto a version that resolves this vulnerability.Fixed in 0.12.7.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-7289.
What software is affected by this vulnerability?
The Teclib-edition Armadito Antivirus software version 0.12.7.2 is affected by this vulnerability.
What is the severity of CVE-2018-7289?
The severity of CVE-2018-7289 is medium with a severity value of 3.3.
How can malware bypass detection with filenames containing pure UTF-16 characters?
Malware with filenames containing pure UTF-16 characters can bypass detection by causing the user-mode service to fail to open the file for scanning after the conversion from Unicode to ANSI is done.
How can I fix the vulnerability in Armadito Antivirus version 0.12.7.2?
To fix the vulnerability, it is recommended to update Armadito Antivirus to a version that addresses the issue.