CVE-2018-6857 is a local privilege escalation vulnerability affecting Sophos SafeGuard Enterprise, SafeGuard Easy, and SafeGuard LAN Crypt products prior to specified versions. An attacker can craft an input buffer to an IOCTL call (0x802022E0), allowing them to write a constant value to a user-controlled address. This manipulation can grant the SE_DEBUG_NAME privilege to the exploit process, enabling interaction with higher-privileged SYSTEM processes and execution of arbitrary code within their security context. The vulnerability carries a CVSSv3 score of 7.8 (High), indicating a significant risk. It requires local access and low privileges (AV:L/PR:L) but has low attack complexity (AC:L), leading to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.00CPE matchmatch criteria | cpe:2.3:a:sophos:safeguard_easy_device_encryption_client:6.00:*:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:a:sophos:safeguard_easy_device_encryption_client:6.10:*:*:*:*:*:*:* | ||
7.00CPE matchmatch criteria | cpe:2.3:a:sophos:safeguard_easy_device_encryption_client:7.00:*:*:*:*:*:*:* | ||
5.60.3CPE matchmatch criteria | cpe:2.3:a:sophos:safeguard_enterprise_client:5.60.3:vs-nfd:*:*:*:*:*:* | ||
6.00CPE matchmatch criteria | cpe:2.3:a:sophos:safeguard_enterprise_client:6.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.