Vulnerability Description
The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet Security 9.4.3202.9 and earlier, ArcaVir 2009 System Protection 9.4.3203.9 and earlier, and ArcaBit 2009 Home Protection 9.4.3204.9 and earlier, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\ps_drv containing arbitrary kernel addresses, as demonstrated using the (1) 0x2A7B802B and possibly (2) 0x2A7B8004 and (3) 0x2A7B802F IOCTLs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arcabit | Arcavir 2009 Antivirus Protection | <= 9.4.3201.9 |
| Arcabit | Arcavir 2009 Home Protection | <= 9.4.3204.9 |
| Arcabit | Arcavir 2009 Internet Security | <= 9.4.3202.9 |
| Arcabit | Arcavir 2009 System Protection | <= 9.4.3203.9 |
Related Weaknesses (CWE)
References
- http://ntinternals.org/ntiadv0814/PsDrv_Exp.zipExploit
- http://ntinternals.org/ntiadv0814/ntiadv0814.htmlExploit
- http://secunia.com/advisories/35260Vendor Advisory
- http://www.securityfocus.com/bid/35100Exploit
- http://www.vupen.com/english/advisories/2009/1428Vendor Advisory
- https://www.exploit-db.com/exploits/8782
- http://ntinternals.org/ntiadv0814/PsDrv_Exp.zipExploit
- http://ntinternals.org/ntiadv0814/ntiadv0814.htmlExploit
- http://secunia.com/advisories/35260Vendor Advisory
- http://www.securityfocus.com/bid/35100Exploit
- http://www.vupen.com/english/advisories/2009/1428Vendor Advisory
- https://www.exploit-db.com/exploits/8782
FAQ
What is CVE-2009-1824?
CVE-2009-1824 is a vulnerability with a CVSS score of 7.2 (HIGH). The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet Security 9.4.3202.9 and earlier, ArcaVir 2009 System Protection 9.4.3203.9 and e...
How severe is CVE-2009-1824?
CVE-2009-1824 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1824?
Check the references section above for vendor advisories and patch information. Affected products include: Arcabit Arcavir 2009 Antivirus Protection, Arcabit Arcavir 2009 Home Protection, Arcabit Arcavir 2009 Internet Security, Arcabit Arcavir 2009 System Protection.