CVE-2018-7289
Armadito Antivirus 0.12.7.2 - Detection Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.
Se ha descubierto un problema en armadito-windows-driver/src/communication.c en Armadito 0.12.7.2. Los malwares con nombres de usuario que contengan caracteres puros en UTF-16 podrían omitir la detección. El servicio user-mode no podrá abrir el archivo para escanearlo una vez se haya realizado la conversión de Unicode a ANSI. Esto ocurre debido a que los caracteres que no pueden convertirse de Unicode se reemplazan con caracteres "?".
Armadito Antivirus version 0.12.7.2 suffers from a detection bypass vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-21 CVE Reserved
- 2018-02-21 CVE Published
- 2023-07-15 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-172: Encoding Error
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/armadito/armadito-windows-driver/issues/5 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44169 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Teclib-edition Search vendor "Teclib-edition" | Armadito Antivirus Search vendor "Teclib-edition" for product "Armadito Antivirus" | 0.12.7.2 Search vendor "Teclib-edition" for product "Armadito Antivirus" and version "0.12.7.2" | - |
Affected
|