MEDIUM · 6.8

CVE-2009-4452

Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and ...

Vulnerability Description

Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse.

CVSS Score

6.8

MEDIUM

AV:L/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Kaspersky LabKaspersky Anti-Virus5.0.712
Kaspersky LabKaspersky Anti-Virus 20098.0.0.454
Kaspersky LabKaspersky Anti-Virus 20109.0.0.463
Kaspersky LabKaspersky Anti-Virus Personal5.0
Kaspersky LabKaspersky Internet Security7.0.1.325
Kaspersky LabKaspersky Internet Security 20098.0.0.506
Kaspersky LabKaspersky Internet Security 20109.0.0.463

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-4452?

CVE-2009-4452 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and ...

How severe is CVE-2009-4452?

CVE-2009-4452 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-4452?

Check the references section above for vendor advisories and patch information. Affected products include: Kaspersky Lab Kaspersky Anti-Virus, Kaspersky Lab Kaspersky Anti-Virus 2009, Kaspersky Lab Kaspersky Anti-Virus 2010, Kaspersky Lab Kaspersky Anti-Virus Personal, Kaspersky Lab Kaspersky Internet Security.