CVE-2018-15437

MEDIUM

Cisco Advanced Malware Protection For Endpoints - Denial of Service

Title source: rule

Description

A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system without being analyzed for threats. The vulnerability is due to improper process resource handling. An attacker could exploit this vulnerability by gaining local access to a system running Microsoft Windows and protected by Cisco Immunet or Cisco AMP for Endpoints and executing a malicious file. A successful exploit could allow the attacker to prevent the scanning services from functioning properly and ultimately prevent the system from being protected from further intrusion.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · cdoswindows
https://www.exploit-db.com/exploits/45829

Scores

CVSS v3 5.5
EPSS 0.0073
EPSS Percentile 72.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-400
Status published
Products (2)
cisco/advanced_malware_protection_for_endpoints
cisco/immunet_for_endpoints
Published Nov 08, 2018
Tracked Since Feb 18, 2026