CVE-2015-4523
critical
CVSS v3
9.3
CVSS v2
9.0
VIR risk
9.3
Description
Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to saving files during analysis.
Predictions
Exploit likelihood
85%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| symantec | malware_analysis_appliance | {"endIncluding":"4.2"} | |
| symantec | malware_analyzer_g2 | {"endIncluding":"3.5"} | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.