CVE-2014-1213
Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protection, cause a denial of service (resource consumption, CPU consumption, and eventual crash) or spoof "ready for update" messages by performing certain operations on mutexes or events including (1) DataUpdateRequest, (2) MmfMutexSAV-****, (3) MmfMutexSAV-Info, (4) ReadyForUpdateSAV-****, (5) ReadyForUpdateSAV-Info, (6) SAV-****, (7) SAV-Info, (8) StateChange, (9) SuspendedSAV-****, (10) SuspendedSAV-Info, (11) UpdateComplete, (12) UpdateMutex, (13) UpdateRequest, or (14) SophosALMonSessionInstance, as demonstrated by triggering a ReadyForUpdateSAV event and modifying the UpdateComplete, UpdateMutex, and UpdateRequest objects.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:N/I:P/A:C
- Puntuación base: 5.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.97%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-264
Referencias
- http://osvdb.org/102762
- http://packetstormsecurity.com/files/125024/Sophos-Anti-Virus-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2014/Feb/1
- http://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1213/
- http://www.securityfocus.com/archive/1/530915/100/0/threaded
- http://www.securityfocus.com/bid/65286
- http://www.securitytracker.com/id/1029713
- http://www.sophos.com/en-us/support/knowledgebase/2300/7200/1031/120401.aspx
- http://osvdb.org/102762
- http://packetstormsecurity.com/files/125024/Sophos-Anti-Virus-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2014/Feb/1
- http://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1213/
- http://www.securityfocus.com/archive/1/530915/100/0/threaded
- http://www.securityfocus.com/bid/65286
- http://www.securitytracker.com/id/1029713
- http://www.sophos.com/en-us/support/knowledgebase/2300/7200/1031/120401.aspx
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-1213",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:C",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 7.8,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-02-10T23:55:05.057",
"references": [
{
"url": "http://osvdb.org/102762",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/125024/Sophos-Anti-Virus-Denial-Of-Service.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Feb/1",
"source": "cve@mitre.org"
},
{
"url": "http://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1213/",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/530915/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/65286",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1029713",
"source": "cve@mitre.org"
},
{
"url": "http://www.sophos.com/en-us/support/knowledgebase/2300/7200/1031/120401.aspx",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/102762",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/125024/Sophos-Anti-Virus-Denial-Of-Service.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Feb/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1213/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/530915/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/65286",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1029713",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sophos.com/en-us/support/knowledgebase/2300/7200/1031/120401.aspx",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protection, cause a denial of service (resource consumption, CPU consumption, and eventual crash) or spoof \"ready for update\" messages by performing certain operations on mutexes or events including (1) DataUpdateRequest, (2) MmfMutexSAV-****, (3) MmfMutexSAV-Info, (4) ReadyForUpdateSAV-****, (5) ReadyForUpdateSAV-Info, (6) SAV-****, (7) SAV-Info, (8) StateChange, (9) SuspendedSAV-****, (10) SuspendedSAV-Info, (11) UpdateComplete, (12) UpdateMutex, (13) UpdateRequest, or (14) SophosALMonSessionInstance, as demonstrated by triggering a ReadyForUpdateSAV event and modifying the UpdateComplete, UpdateMutex, and UpdateRequest objects."
},
{
"lang": "es",
"value": "El motor de Sophos Anti-Virus (SAVi) anterior a 3.50.1, utilizado en VDL 4.97G 9.7.x anterior a 9.7.9, 10.0.x anterior a 10.0.11 y 10.3.x anterior a 10.3.1 no establece una ACL para cietos objetos globales y de sesión, lo que permite a usuarios locales evadir la protección Anti-Virus, causa una denegación de servicio (consumo de recursos, consumo de CPU y finalmente una caída) o falsifica mensajes de \"preparado para actualización\" mediante ciertas operaciones realizadas en mutexes o eventos incluyendo (1) DataUpdateRequest, (2) MmfMutexSAV-****, (3) MmfMutexSAV-Info, (4) ReadyForUpdateSAV-****, (5) ReadyForUpdateSAV-Info, (6) SAV-****, (7) SAV-Info, (8) StateChange, (9) SuspendedSAV-****, (10) SuspendedSAV-Info, (11) UpdateComplete, (12) UpdateMutex, (13) UpdateRequest o (14) SophosALMonSessionInstance, demostrado mediante la provocación de un evento ReadyForUpdateSAV y modificación de objetos UpdateComplete, UpdateMutex y UpdateRequest."
}
],
"lastModified": "2026-06-17T00:04:32.383",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sophos:scanning_engine:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DA592E6-2BA6-4A69-9D6A-523921D6E45D",
"versionEndIncluding": "3.48"
},
{
"criteria": "cpe:2.3:a:sophos:sophos_anti-virus:10.0.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A5C5A60-26CE-4334-A911-382A452459AD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}