7.5
CVSSv2

CVE-2004-0552

Published: 03/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.

Vulnerable Product Search on Vulmon Subscribe to Product

sophos small business suite

Exploits

source: wwwsecurityfocuscom/bid/11236/info Sophos Anti-Virus is affected by a reserved MS-DOS name virus scan evasion vulnerability This issue is due to a design error that allows certain files to avoid being scanned An attacker may leverage this issue to bypass the scanner protection provided by the vulnerable anti-virus scanner, givi ...