CVE-2008-1737

Sophos Anti-Virus 7.x - Denial of Service via NtCreateKey SSDT Hook

Title source: llm
STIX 2.1

Description

Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboot with the product disabled) and possibly gain privileges via a zero value in a certain length field in the ObjectAttributes argument to the NtCreateKey hooked System Service Descriptor Table (SSDT) function.

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29996
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42083
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28743
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3838
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1381
Various Sources x_refsource_misc
http://www.coresecurity.com/?action=item&id=2249
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/491405/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1019945

Scores

EPSS 0.0006
EPSS Percentile 17.7%

Details

CWE
CWE-20
Status published
Products (1)
sophos/anti-virus 7.0.5
Published Apr 30, 2008
Tracked Since Feb 18, 2026