CVE-2016-9038: Sophos Invincea-X
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result in kernel memory corruption, which could result in privilege escalation. An attacker needs to execute a special application locally to trigger this vulnerability.
Affected products
- Sophos Invincea-X: version 6.1.3-24058 only
Published 2018-04-24. Last modified 2026-06-17.