Vulnerability Description
Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kaspersky Lab | Kaspersky Anti-Virus | 6.0 |
Related Weaknesses (CWE)
References
- http://kartoffel.reversemode.com/downloads/kaspersky_klim5_plugin.zip
- http://secunia.com/advisories/33788Vendor Advisory
- http://www.reversemode.com/index.php?option=com_content&task=view&id=60&Itemid=1
- http://www.securityfocus.com/archive/1/500606/100/0/threaded
- http://www.securityfocus.com/bid/33561Exploit
- http://www.securitytracker.com/id?1021661
- http://www.wintercore.com/advisories/advisory_W020209.html
- http://kartoffel.reversemode.com/downloads/kaspersky_klim5_plugin.zip
- http://secunia.com/advisories/33788Vendor Advisory
- http://www.reversemode.com/index.php?option=com_content&task=view&id=60&Itemid=1
- http://www.securityfocus.com/archive/1/500606/100/0/threaded
- http://www.securityfocus.com/bid/33561Exploit
- http://www.securitytracker.com/id?1021661
- http://www.wintercore.com/advisories/advisory_W020209.html
FAQ
What is CVE-2009-0449?
CVE-2009-0449 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call.
How severe is CVE-2009-0449?
CVE-2009-0449 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0449?
Check the references section above for vendor advisories and patch information. Affected products include: Kaspersky Lab Kaspersky Anti-Virus.