First published: Wed Aug 10 2022(Updated: )
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certain WithSecure products unpacker function crashes which leads to scanning engine crash. The exploit can be triggered remotely by an attacker.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Elements Endpoint Detection And Response | ||
F-secure Elements Endpoint Protection | ||
Apple macOS | ||
Microsoft Windows | ||
F-Secure Atlant | ||
F-secure Cloud Protection For Salesforce | ||
F-secure Elements Collaboration Protection | ||
F-secure Internet Gatekeeper | ||
F-Secure Linux Security | ||
F-secure Linux Security 64 |
FIX No User action is required. The required fix has been published through automatic update channel with Capricorn database on 2022-07-29_13
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28881 is a Denial-of-Service (DoS) vulnerability in F-Secure Atlant.
CVE-2022-28881 can lead to a scanning engine crash in certain F-Secure products.
F-Secure Elements Endpoint Detection And Response, F-Secure Elements Endpoint Protection, F-Secure Atlant, F-Secure Cloud Protection For Salesforce, F-Secure Elements Collaboration Protection, F-Secure Internet Gatekeeper, F-Secure Linux Security, and F-Secure Linux Security 64 are affected by CVE-2022-28881.
CVE-2022-28881 has a severity rating of 7.5 (high).
You can find more information about CVE-2022-28881 in the F-Secure security advisories and WithSecure support security advisories.