CVE-2010-1591
Summary
| CVE | CVE-2010-1591 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-28 23:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module, reachable through \Device\RSNTGDI. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rising-global | Rising Antivirus | 2008 | All | All | All |
| Application | Rising-global | Rising Antivirus | 2009 | All | All | All |
| Application | Rising-global | Rising Antivirus | 2010 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rising Antivirus Multiple IOCTL Request Handling Local Privilege Escalation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/61946 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| NTIADV0805 - RISING Antivirus 2008/2009/2010 Multiple Privilege Escalation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.ntinternals.org | Exploit |
| NTIADV0902 - RISING Antivirus 2008/2009/2010 Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.ntinternals.org | Exploit |
| Rising Antivirus Device Drivers IOCTL Handling Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.