PT-2006-5676 · Kaspersky · Klick.Sys+3

Published

2006-10-20

·

Updated

2018-10-17

·

CVE-2006-4926

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kaspersky Labs Anti-Virus version 6.0.0.303 KLICK.SYS device driver version 2.0.0.281 KLIN.SYS device driver version 2.0.0.281
Description The issue allows local users to execute arbitrary code via a crafted Irp structure with invalid addresses in the "0x80052110" IOCTL. This is related to the NDIS-TDI Hooking Engine used in certain device drivers.
Recommendations For Kaspersky Labs Anti-Virus version 6.0.0.303, update the KLICK.SYS and KLIN.SYS device drivers to a version that does not contain the vulnerable NDIS-TDI Hooking Engine. For KLICK.SYS device driver version 2.0.0.281, consider disabling the device driver until a patch is available. For KLIN.SYS device driver version 2.0.0.281, restrict access to the vulnerable IOCTL "0x80052110" to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4926

Affected Products

Klick.Sys
Klin.Sys
Kaspersky Anti-Virus
Kaspersky Labs Anti-Virus