LOW🇵🇱 Wersja polska

CVE-2018-7289

CVSS 3.3v3.0pub. 2018-02-21upd. 2024-11-21

An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  • Teclib Edition Armadito Antivirus

    APP
    Teclib-Edition
    0.12.7.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-23489CRITICAL9.1PL ✓same vendor

RCE przez tworzenie dropdownów w pluginie Fields dla GLPI

CVE-2021-43779CRITICAL9.9PL ✓same vendor

RCE w pluginie GLPI Addressing — command injection po uwierzytelnieniu

CVE-2019-12723CRITICAL9.8PL ✓same vendor

SQL Injection w Teclib Fields plugin dla GLPI — dostęp bez uwierzytelnienia

CVE-2019-10231CRITICAL9.8PL ✓same vendor

Pominięcie uwierzytelnienia w GLPI przez PHP type juggling

CVE-2019-10232CRITICAL9.8PL ✓same vendor

SQL injection w GLPI via parametr 'cycle' w skrypcie unlock_tasks.php