Description
Race condition in Sophos Endpoint Security and Control 9.0.5 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: the vendor disputes this issue because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T03:07:37.755Z
Reserved: 2012-08-25T00:00:00.000Z
Link: CVE-2010-5177
No data.
Status : Deferred
Published: 2012-08-25T21:55:03.667
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-5177
No data.
OpenCVE Enrichment
No data.
Weaknesses