Multiple Kaspersky Products 'kl1.sys' Local Stack Based Buffer Overflow Vulnerability
BID:29544
Info
Multiple Kaspersky Products 'kl1.sys' Local Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 29544 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1518 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jun 04 2008 12:00AM |
| Credit: | Tobias Klein |
| Vulnerable: |
Kaspersky Internet Security 7.0 Kaspersky Internet Security 6.0 Kaspersky Anti-Virus for Windows Workstation 6.0 Kaspersky Anti-Virus 7.0 |
| Not Vulnerable: | |
Discussion
Multiple Kaspersky Products 'kl1.sys' Local Stack Based Buffer Overflow Vulnerability
Multiple Kaspersky products are prone to a local stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects versions in the following product groups:
Anti-Virus 6.0 and 7.0
Anti-Virus for Windows Workstations 6.0
Internet Security 6.0 and 7.0
Multiple Kaspersky products are prone to a local stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects versions in the following product groups:
Anti-Virus 6.0 and 7.0
Anti-Virus for Windows Workstations 6.0
Internet Security 6.0 and 7.0
Exploit / POC
Multiple Kaspersky Products 'kl1.sys' Local Stack Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Kaspersky Products 'kl1.sys' Local Stack Based Buffer Overflow Vulnerability
Solution:
The vendor released a patch that is available via the automatic updating module. Please see the references for more information.
Solution:
The vendor released a patch that is available via the automatic updating module. Please see the references for more information.
References
Multiple Kaspersky Products 'kl1.sys' Local Stack Based Buffer Overflow Vulnerability
References:
References:
- Kaspersky Homepage (Kaspersky)
- iDefense Security Advisory 06.04.08: Kaspersky Internet Security IOCTL Stack Bas (iDefense Labs
) - Kaspersky Internet Security IOCTL Stack Based Buffer Overflow Vulnerability (iDefense Labs)
- Low-risk vulnerability in kl1.sys driver is closed (Kaspersky)