CVE-2018-4012: Webroot Brightcloud
High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.
An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.
Affected products
- Webroot Brightcloud: any version
Published 2019-01-03. Last modified 2026-06-17.