github.com
https://github.com/armadito/armadito-windows-driver/issues/5 CVE-2018-7289
LOW
Armadito Antivirus 0.12.7.2 - Detection Bypass
Record summary
CVE-2018-7289 has a selected CVSS score of 3.3 (low); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBArmadito Antivirus 0.12.7.2 - Detection BypassExploitDB exploitby Souhail HammouNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7289 44169exploit
https://www.exploit-db.com/exploits/44169