Sophos Anti-Virus 3.x - Reserved MS-DOS Name Scan Evasion

EDB-ID:

24623


Platform:

Windows

Published:

2004-09-22

source: http://www.securityfocus.com/bid/11236/info

Sophos Anti-Virus is affected by a reserved MS-DOS name virus scan evasion vulnerability. This issue is due to a design error that allows certain files to avoid being scanned.

An attacker may leverage this issue to bypass the scanner protection provided by the vulnerable anti-virus scanner, giving users a false sense of security. It is reported that this issue can be leveraged to bypass both file system and email virus scanners, allowing this issue to be exploited remotely.

copy source \\.\C:\aux