PT-2009-1475 · G Data · G Data Totalcare+2

Published

2009-01-28

·

Updated

2017-08-08

·

CVE-2008-6000

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions G DATA AntiVirus versions 2008 G DATA InternetSecurity versions 2008 G DATA TotalCare versions 2008
Description The issue allows local users to cause a denial of service or gain privileges via a crafted IOCTL request. This is achieved by populating kernel registers with IOCTL 0x8317001c input values in the GDTdiIcpt.sys driver. The KeSetEvent function can be executed with modified register contents.
Recommendations For G DATA AntiVirus version 2008, consider disabling the GDTdiIcpt.sys driver until a patch is available. For G DATA InternetSecurity version 2008, restrict access to the IOCTL 0x8317001c request to minimize the risk of exploitation. For G DATA TotalCare version 2008, avoid using the KeSetEvent function with modified register contents until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6000

Affected Products

G Data Antivirus
G Data Internetsecurity
G Data Totalcare