CVE-2008-0792

UnknownEPSS 2.17%

Last modified

CVE-2008-0792 is a vulnerability of currently unknown severity. Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.. EPSS estimates a 2.17% chance of exploitation in the next 30 days.

Description

Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.

Metrics

EPSS Probability
2.17%

80.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
F-SecureF-Secure Anti-Virus2006
F-SecureF-Secure Anti-Virus2007
F-SecureF-Secure Anti-Virus2008
F-SecureF-Secure Anti-Virus Client Security6.03
F-SecureF-Secure Anti-Virus Client Security6.04
F-SecureF-Secure Anti-Virus Client Security7.01
F-SecureF-Secure Anti-Virus Client Security7.10
F-SecureF-Secure Anti-Virus For Linux4.65
F-SecureF-Secure Anti-Virus For Workstations5.44
F-SecureF-Secure Anti-Virus For Workstations7.00
F-SecureF-Secure Anti-Virus For Workstations7.10
F-SecureF-Secure Anti-Virus Linux Client Security5.52
F-SecureF-Secure Anti-Virus Linux Client Security5.53
F-SecureF-Secure Internet Security2006
F-SecureF-Secure Internet Security2007
F-SecureF-Secure Internet Security2008
F-SecureF-Secure Protection Service For Business<= 3.00
F-SecureF-Secure Protection Service For Consumers<= 7.00

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-0792?
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.
How severe is CVE-2008-0792?
Severity scoring for CVE-2008-0792 is pending analysis. The EPSS model estimates a 2.17% probability of exploitation in the next 30 days.
How do I fix CVE-2008-0792?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-0792?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST