vendor:
Armadito Antivirus
by:
Souhail Hammou
3.3
CVSS
LOW
Bypass Detection
20
CWE
Product Name: Armadito Antivirus
Affected Version From: 0.12.7.2
Affected Version To: 0.12.7.2
Patch Exists: YES
Related CWE: CVE-2018-7289
CPE: a:teclib:armadito_antivirus
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Armadito Antivirus – Malware Detection Bypass
An issue was discovered in armadito-windows-driver/src/communication.c affecting Armadito 0.12.7.2 and previous versions. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI.
Mitigation:
Upgrade to the latest version of Armadito Antivirus to fix the issue.