Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-0937.
AI-analyzed exploit summary This PoC exploits a vulnerability in multiple antivirus engines (CVE-2004-0937) by corrupting ZIP file headers, causing denial-of-service or potential code execution when the file is scanned. It patches specific offsets in local and central ZIP headers to trigger the vulnerability.
Description
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Exploits (1)
This PoC exploits a vulnerability in multiple antivirus engines (CVE-2004-0937) by corrupting ZIP file headers, causing denial-of-service or potential code execution when the file is scanned. It patches specific offsets in local and central ZIP headers to trigger the vulnerability.