PT-2007-6183 · Kaspersky+1 · Kaspersky Anti-Virus+2
Published
2007-09-26
·
Updated
2011-03-08
·
CVE-2007-5086
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Kaspersky Anti-Virus (KAV) and Internet Security version 7.0 build 125
Description
The issue arises from improper validation of certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, allowing local users to cause a denial of service (crash) via various kernel SSDT hooks in kylif.sys, including
NtUserSendInput, LoadLibraryA, NtOpenProcess, NtOpenThread, NtTerminateProcess, NtUserFindWindowEx, and NtUserBuildHwndList. Additionally, the NtDuplicateObject (DuplicateHandle) kernel SSDT hook is potentially affected.Recommendations
For Kaspersky Anti-Virus (KAV) and Internet Security version 7.0 build 125, consider disabling the vulnerable kernel SSDT hooks in kylif.sys as a temporary workaround until a patch is available. Restrict access to the
NtUserSendInput, LoadLibraryA, NtOpenProcess, NtOpenThread, NtTerminateProcess, NtUserFindWindowEx, and NtUserBuildHwndList functions to minimize the risk of exploitation. Avoid using the NtDuplicateObject (DuplicateHandle) function in the affected kernel SSDT hook until the issue is resolved.Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kaspersky Anti-Virus
Kaspersky Internet Security
Windows