CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
Low
EPSS
Percentile
99.5%
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0, and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a modified reserved3 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
Vendor | Product | Version | CPE |
---|---|---|---|
emsisoft | anti-malware | 5.1.0.1 | cpe:2.3:a:emsisoft:anti-malware:5.1.0.1:*:*:*:*:*:*:* |
ikarus | ikarus_virus_utilities_t3_command_line_scanner | 1.1.97.0 | cpe:2.3:a:ikarus:ikarus_virus_utilities_t3_command_line_scanner:1.1.97.0:*:*:*:*:*:*:* |
sophos | sophos_anti-virus | 4.61.0 | cpe:2.3:a:sophos:sophos_anti-virus:4.61.0:*:*:*:*:*:*:* |