PT-2010-4787 · Kingsoft · Kingsoft Antivirus
Lufeng Li
·
Published
2010-09-15
·
Updated
2018-10-30
·
CVE-2010-3396
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Kingsoft Antivirus versions 2010.04.26.648 and earlier
Description
The issue is related to a buffer overflow in the kavfm.sys component. This can be exploited by local users to execute arbitrary code by providing a long argument to the IOCTL 0x80030004.
Recommendations
For Kingsoft Antivirus versions 2010.04.26.648 and earlier, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict access to the IOCTL 0x80030004 to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kingsoft Antivirus