Remote Code Execution Vulnerability in Sophos Anti-Virus Products
CVE-2006-0994
Currently unrated
Summary
Sophos Anti-Virus products, specifically versions 5.x before 5.2.1 and 4.x before 4.05, are susceptible to a vulnerability that allows remote attackers to execute arbitrary code. This issue arises when cabinet file inspection is enabled, enabling exploitation through a crafted CAB file that contains invalid folder count values. The resulting malformed data can lead to heap corruption, potentially compromising the system's integrity.
References
EPSS Score
42% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved