CVE-2017-6008
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
13/09/2017
Last modified:
20/04/2025
Description
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sophos:hitmanpro:*:*:*:*:*:*:*:* | 3.7.20 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/cbayet/Exploit-CVE-2017-6008
- https://trackwatch.com/kernel-pool-overflow-exploitation-in-real-world-windows-10/
- https://trackwatch.com/kernel-pool-overflow-exploitation-in-real-world-windows-7/
- https://www.exploit-db.com/exploits/43057/
- https://www.nuitduhack.com/fr/planning/talk_10
- https://github.com/cbayet/Exploit-CVE-2017-6008
- https://trackwatch.com/kernel-pool-overflow-exploitation-in-real-world-windows-10/
- https://trackwatch.com/kernel-pool-overflow-exploitation-in-real-world-windows-7/
- https://www.exploit-db.com/exploits/43057/
- https://www.nuitduhack.com/fr/planning/talk_10



