CVE-2018-4012: Webroot Brightcloud

High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.

An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.

Affected products

Published 2019-01-03. Last modified 2026-06-17.