Sophos Anti-Virus For Windows CAB File Scan Evasion

medium Nessus Plugin ID 39448

Synopsis

The remote host is running antivirus software with a file scan evasion vulnerability.

Description

According to its engine number, the version of Sophos Anti-Virus running on the remote Windows host has a scan evasion vulnerability.
Specially crafted CAB files can exploit this to bypass antivirus scanning.

Solution

Upgrade to Sophos Anti-Virus engine version 2.87.1 or later.

Plugin Details

Severity: Medium

ID: 39448

File Name: sophos_2_87_1.nasl

Version: 1.11

Type: local

Agent: windows

Family: Windows

Published: 6/18/2009

Updated: 8/7/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:sophos:sophos_anti-virus

Required KB Items: Antivirus/Sophos/installed, Antivirus/Sophos/eng_ver

Exploit Ease: No known exploits are available

Patch Publication Date: 6/16/2009

Reference Information

BID: 35402

Secunia: 35467