SB2018121822 - Denial of service in Sysmon



SB2018121822 - Denial of service in Sysmon

Published: December 18, 2018

Security Bulletin ID SB2018121822
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Memory leak (CVE-ID: N/A)

The vulnerability allows a remote attacker to cause DoS condition.

The weakness exists due to Sysmon's driver (SysmonDrv.sys) consumes new area in Nonpaged pool memory every time configuration reloads, but driver does not free old area in Nonpaged pool memory. A remote attacker can trigger memory leak and cause the service to crash.

Remediation

Install update from vendor's website.