Issues in Memory Handling and Access Validation

This document details the vulnerability identified in some driver components.

Severity: High

Attack Vector: Local

Fix Build: Upgrade to 11.1.2408.7

Released on: 8th November 2024

Reported by: Alex Oudenaarden of Northwave Cyber Security via Zoho Corp Bug Bounty Program

What was the problem?

An access validation issue in some driver components can lead to unauthorized processes interacting with the driver. Alongside, a poor memory handling issue has also been fixed, which could cause memory corruption within the kernel.

Cloud Applicability: This issue is not applicable to Cloud versions.

How do I fix it?

Upgrading to the latest version is strongly advised due to this vulnerability's severity. To upgrade, follow the steps below:

  • Log in to the product console, and click on your current build number in the top right corner.
  • You'll be able to find the latest build applicable to you. Download the PPM and update.

If you have any questions or require additional information regarding this update, please don't hesitate to contact our support.