peter bassill · operator
$ cve CVE-2004-0552 JSON

CVE-2004-0552 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 23.9% (pctl 98)

Patch early

A public exploit exists.

Description

Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS23.87% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-03
Last modified2026-06-16

Affected (1)

VendorProduct
sophossmall business suite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD