PT-2009-6293 · Kaspersky · Kaspersky Anti-Virus

Published

2009-11-30

·

Updated

2018-10-10

·

CVE-2009-4114

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Kaspersky Anti-Virus versions 9.0.0.463 through 9.0.0.735
Description The issue is related to the improper validation of input to IOCTL 0x0022c008 in the kl1.sys component. This allows local users to cause a denial of service, resulting in a system crash, by sending IOCTL requests with crafted kernel addresses that trigger memory corruption. The issue might be related to the klavemu.kdl component.
Recommendations For Kaspersky Anti-Virus versions 9.0.0.463 through 9.0.0.735, update to version 9.0.0.736 or later to resolve the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4114

Affected Products

Kaspersky Anti-Virus