PT-2007-6183 · Kaspersky+1 · Kaspersky Anti-Virus+2

Publicado

2007-09-26

·

Atualizado

2011-03-08

·

CVE-2007-5086

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Kaspersky Anti-Virus (KAV) and Internet Security version 7.0 build 125
Description The issue arises from improper validation of certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, allowing local users to cause a denial of service (crash) via various kernel SSDT hooks in kylif.sys, including NtUserSendInput, LoadLibraryA, NtOpenProcess, NtOpenThread, NtTerminateProcess, NtUserFindWindowEx, and NtUserBuildHwndList. Additionally, the NtDuplicateObject (DuplicateHandle) kernel SSDT hook is potentially affected.
Recommendations For Kaspersky Anti-Virus (KAV) and Internet Security version 7.0 build 125, consider disabling the vulnerable kernel SSDT hooks in kylif.sys as a temporary workaround until a patch is available. Restrict access to the NtUserSendInput, LoadLibraryA, NtOpenProcess, NtOpenThread, NtTerminateProcess, NtUserFindWindowEx, and NtUserBuildHwndList functions to minimize the risk of exploitation. Avoid using the NtDuplicateObject (DuplicateHandle) function in the affected kernel SSDT hook until the issue is resolved.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5086

Produtos afetados

Kaspersky Anti-Virus
Kaspersky Internet Security
Windows