Record summary

CVE-2018-7289 has a selected CVSS score of 3.3 (low); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBArmadito Antivirus 0.12.7.2 - Detection BypassExploitDB exploitby Souhail HammouNot analyzed1 file
ExploitDB

PoC details

References

3