PT-2006-5676 · Kaspersky · Klick.Sys+3
Publicado
2006-10-20
·
Atualizado
2018-10-17
·
CVE-2006-4926
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Kaspersky Labs Anti-Virus version 6.0.0.303
KLICK.SYS device driver version 2.0.0.281
KLIN.SYS device driver version 2.0.0.281
Description
The issue allows local users to execute arbitrary code via a crafted Irp structure with invalid addresses in the "0x80052110" IOCTL. This is related to the NDIS-TDI Hooking Engine used in certain device drivers.
Recommendations
For Kaspersky Labs Anti-Virus version 6.0.0.303, update the KLICK.SYS and KLIN.SYS device drivers to a version that does not contain the vulnerable NDIS-TDI Hooking Engine.
For KLICK.SYS device driver version 2.0.0.281, consider disabling the device driver until a patch is available.
For KLIN.SYS device driver version 2.0.0.281, restrict access to the vulnerable IOCTL "0x80052110" to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Klick.Sys
Klin.Sys
Kaspersky Anti-Virus
Kaspersky Labs Anti-Virus