First published: Wed Aug 10 2022(Updated: )
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certain WithSecure products unpacker function crashes which leads to scanning engine crash. The exploit can be triggered remotely by an attacker.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cybereason Endpoint Detection And Response | ||
F-Secure Endpoint Protection | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
F-Secure Atlant | ||
F-Secure Cloud Protection for Salesforce | ||
F-Secure Elements Collaboration Protection | ||
F-Secure Internet Gatekeeper for Linux | ||
F-Secure Linux Security 64 | ||
F-Secure Linux Security |
FIX No User action is required. The required fix has been published through automatic update channel with Capricorn database on 2022-07-29_13
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28881 is a Denial-of-Service (DoS) vulnerability in F-Secure Atlant.
CVE-2022-28881 can lead to a scanning engine crash in certain F-Secure products.
F-Secure Elements Endpoint Detection And Response, F-Secure Elements Endpoint Protection, F-Secure Atlant, F-Secure Cloud Protection For Salesforce, F-Secure Elements Collaboration Protection, F-Secure Internet Gatekeeper, F-Secure Linux Security, and F-Secure Linux Security 64 are affected by CVE-2022-28881.
CVE-2022-28881 has a severity rating of 7.5 (high).
You can find more information about CVE-2022-28881 in the F-Secure security advisories and WithSecure support security advisories.