PT-2006-5676 · Kaspersky · Klick.Sys+3
Published
2006-10-20
·
Updated
2018-10-17
·
CVE-2006-4926
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Kaspersky Labs Anti-Virus version 6.0.0.303
KLICK.SYS device driver version 2.0.0.281
KLIN.SYS device driver version 2.0.0.281
Description
The issue allows local users to execute arbitrary code via a crafted Irp structure with invalid addresses in the "0x80052110" IOCTL. This is related to the NDIS-TDI Hooking Engine used in certain device drivers.
Recommendations
For Kaspersky Labs Anti-Virus version 6.0.0.303, update the KLICK.SYS and KLIN.SYS device drivers to a version that does not contain the vulnerable NDIS-TDI Hooking Engine.
For KLICK.SYS device driver version 2.0.0.281, consider disabling the device driver until a patch is available.
For KLIN.SYS device driver version 2.0.0.281, restrict access to the vulnerable IOCTL "0x80052110" to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Klick.Sys
Klin.Sys
Kaspersky Anti-Virus
Kaspersky Labs Anti-Virus