An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NTeclib Edition Armadito Antivirus
APPTeclib-Edition0.12.7.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-23489CRITICAL9.1PL ✓same vendor
RCE przez tworzenie dropdownów w pluginie Fields dla GLPI
CVE-2021-43779CRITICAL9.9PL ✓same vendor
RCE w pluginie GLPI Addressing — command injection po uwierzytelnieniu
CVE-2019-12723CRITICAL9.8PL ✓same vendor
SQL Injection w Teclib Fields plugin dla GLPI — dostęp bez uwierzytelnienia
CVE-2019-10231CRITICAL9.8PL ✓same vendor
Pominięcie uwierzytelnienia w GLPI przez PHP type juggling
CVE-2019-10232CRITICAL9.8PL ✓same vendor
SQL injection w GLPI via parametr 'cycle' w skrypcie unlock_tasks.php