Vulnerabilities > CVE-2020-8508 - Out-of-bounds Write vulnerability in Norman Malware Cleaner 2.08.08

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
norman
CWE-787

Summary

nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of function pointers between user and kernel mode is mishandled.

Vulnerable Configurations

Part Description Count
Application
Norman
1

Common Weakness Enumeration (CWE)