First published: Mon May 23 2022(Updated: )
Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-Secure Atlant | ||
F-secure Elements Endpoint Protection | ||
F-Secure Linux Security | ||
Apple macOS | ||
Microsoft Windows | ||
Withsecure Cloud Protection For Salesforce | ||
Withsecure Elements Collaboration Protection |
FIX No User action is required. The required fix has been published through automatic update channel with Capricorn database on 2022-05-16_12
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28874 is a Denial-of-Service vulnerability discovered in F-Secure Atlant and certain WithSecure products.
The severity of CVE-2022-28874 is high, with a CVSS score of 7.5.
The affected software includes F-Secure Atlant, F-Secure Elements Endpoint Protection, F-Secure Linux Security, Withsecure Cloud Protection For Salesforce, and Withsecure Elements Collaboration Protection.
The exploit can be triggered remotely by an attacker using fuzzed PE32-bit files, causing memory corruption and heap buffer overflow, ultimately crashing the scanning engine.
To fix CVE-2022-28874, it is recommended to apply the latest security patches or updates provided by the software vendors F-Secure and WithSecure.