« Volver al listado

CVE-2008-5048

Estado: ModificadaAlta (7.2)—

Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long inputs to the 0x00222494 IOCTL.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-5048",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-11-13T02:30:00.823",
  "references": [
    {
      "url": "http://secunia.com/advisories/32669",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ntinternals.org/ntiadv0802/ntiadv0802.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/32202",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46464",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/32669",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ntinternals.org/ntiadv0802/ntiadv0802.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/32202",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46464",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long inputs to the 0x00222494 IOCTL."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en Atepmon.sys de ISecSoft Anti-Trojan Elite v4.2.1 y anteriores, y puede que v4.2.2; permite a los usuarios locales provocar una denegación de servicio (caída) y puede que ejecutar código de su elección a través de inserciones largas al IOCTL 0x00222494."
    }
  ],
  "lastModified": "2026-06-16T22:59:09.157",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:isecsoft:anti-trojan_elite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A87EC17-F727-4E3A-A2B7-D844FA98B7D5",
              "versionEndIncluding": "4.2.2"
            },
            {
              "criteria": "cpe:2.3:a:isecsoft:anti-trojan_elite:4.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EA0B4FA-A85F-4A8D-9C11-AD0864EB1031"
            },
            {
              "criteria": "cpe:2.3:a:isecsoft:anti-trojan_elite:4.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19A3EE89-BD4F-4654-9252-C6B0073D35D9"
            },
            {
              "criteria": "cpe:2.3:a:isecsoft:anti-trojan_elite:4.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74C7A54A-0272-4FA5-80C6-2CC8BEF87F40"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}