First published: Fri Aug 05 2022(Updated: )
A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Elements Endpoint Detection And Response | ||
F-secure Elements Endpoint Protection | ||
Apple macOS | ||
Microsoft Windows | ||
F-Secure Atlant | ||
F-secure Cloud Protection For Salesforce | ||
F-secure Elements Collaboration Protection | ||
F-secure Internet Gatekeeper | ||
F-Secure Linux Security | ||
F-secure Linux Security 64 |
FIX No User action is required. The required fix has been published through automatic update channel with Capricorn database on 2022-07-29_13
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28880 is a Denial-of-Service vulnerability discovered in F-Secure Atlant and certain WithSecure products.
The affected software includes F-Secure Atlant, F-Secure Elements Endpoint Detection And Response, F-Secure Elements Endpoint Protection, F-secure Cloud Protection For Salesforce, F-secure Elements Collaboration Protection, F-secure Internet Gatekeeper, F-Secure Linux Security, and F-secure Linux Security 64.
CVE-2022-28880 has a severity rating of 7.5 (high).
CVE-2022-28880 can be triggered remotely by an attacker while scanning fuzzed PE32-bit files.
You can find more information about CVE-2022-28880 in the F-Secure vulnerability reward program hall of fame and the WithSecure expertise page.