AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-7441

HIGH · CVSS 7.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-09-13 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2017-7441
Severity
HIGH
CVSS
7.8
EPSS
0.46%

Original Filing — NVD Description

In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0 might lead to kernel data leaks. Because the leak occurs at the driver level, an attacker can use this vulnerability to leak some critical information about the machine such as nt!ExpPoolQuotaCookie.