PT-2007-6183 · Kaspersky+1 · Kaspersky Anti-Virus+2
Publicado
2007-09-26
·
Atualizado
2011-03-08
·
CVE-2007-5086
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Kaspersky Anti-Virus (KAV) and Internet Security version 7.0 build 125
Description
The issue arises from improper validation of certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, allowing local users to cause a denial of service (crash) via various kernel SSDT hooks in kylif.sys, including
NtUserSendInput, LoadLibraryA, NtOpenProcess, NtOpenThread, NtTerminateProcess, NtUserFindWindowEx, and NtUserBuildHwndList. Additionally, the NtDuplicateObject (DuplicateHandle) kernel SSDT hook is potentially affected.Recommendations
For Kaspersky Anti-Virus (KAV) and Internet Security version 7.0 build 125, consider disabling the vulnerable kernel SSDT hooks in kylif.sys as a temporary workaround until a patch is available. Restrict access to the
NtUserSendInput, LoadLibraryA, NtOpenProcess, NtOpenThread, NtTerminateProcess, NtUserFindWindowEx, and NtUserBuildHwndList functions to minimize the risk of exploitation. Avoid using the NtDuplicateObject (DuplicateHandle) function in the affected kernel SSDT hook until the issue is resolved.Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kaspersky Anti-Virus
Kaspersky Internet Security
Windows