PT-2010-2456 · Avast · Avast!

Tobias Klein

·

Published

2010-02-25

·

Updated

2018-10-10

·

CVE-2010-0705

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions avast! versions 4.8 through 4.8.1368.0 avast! version 5.0 before 5.0.418.0
Description The issue is related to the Aavmker4.sys driver in avast!, which does not properly validate input to IOCTL 0xb2d60030. This allows local users to cause a denial of service, resulting in a system crash, or execute arbitrary code to gain privileges. The exploitation is done via IOCTL requests using crafted kernel addresses that trigger memory corruption.
Recommendations For avast! versions 4.8 through 4.8.1368.0, update to version 4.8.1368.1 or later. For avast! version 5.0 before 5.0.418.0, update to version 5.0.418.0 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0705

Affected Products

Avast!