CVE-2007-1112
Summary
| CVE | CVE-2007-1112 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-06 00:19:00 UTC |
| Updated | 2018-10-16 16:36:00 UTC |
| Description | Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kaspersky Lab | Kaspersky Anti-virus | 6.0 | All | windows_workstation | All |
| Application | Kaspersky Lab | Kaspersky Anti-virus | 6.0 | All | windows_workstation | All |
| Application | Kaspersky Lab | Kaspersky Internet Security | 6.0 | maintenance_pack_2 | All | All |
| Application | Kaspersky Lab | Kaspersky Internet Security | 6.0 | maintenance_pack_2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Kaspersky AntiVirus Prod60 ActiveX Control Arbitrary File Exfiltration Vulnerability | BID | www.securityfocus.com | |
| Kaspersky Anti-Virus ActiveX Controls Let Remote Users View and Delete Files - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| ZDI-07-014 | MISC | www.zerodayinitiative.com | Vendor Advisory |
| Kaspersky Anti-Virus 6.0, Kaspersky Internet Security 6.0 - 5 vulnerabilities fixed in Maintenance Pack 2.0 build 6.0.2.614 | CONFIRM | www.kaspersky.com | Patch |
| Kaspersky Internet Security ActiveX Controls Let Remote Users View and Delete Files - SecurityTracker | SECTRACK | www.securitytracker.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Kaspersky Products Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.