CVE-2004-0552
Sophos Anti-Virus 3.x - Reserved MS-DOS Name Scan Evasion
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.
Sophos Small Business Suite 1.00 para Windows no maneja adecuadamente ficheros cuyos tamaños contienen nombres reservados de MS-DOS, como (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, lo que puede permitir que código malicioso evite la detección cuando es instalado, copiado o ejecutado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-06-11 CVE Reserved
- 2004-09-22 First Exploit
- 2004-09-28 CVE Published
- 2024-04-05 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.idefense.com/application/poi/display?id=143&type=vulnerabilities | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17468 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/24623 | 2004-09-22 | |
http://www.seifried.org/security/advisories/kssa-005.html | 2024-08-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sophos Search vendor "Sophos" | Small Business Suite Search vendor "Sophos" for product "Small Business Suite" | <= 1.00 Search vendor "Sophos" for product "Small Business Suite" and version " <= 1.00" | - |
Affected
|