Kaspersky Anti-Virus 'kl1.sys' Driver Local Privilege Escalation Vulnerability
BID:37044
Info
Kaspersky Anti-Virus 'kl1.sys' Driver Local Privilege Escalation Vulnerability
| Bugtraq ID: | 37044 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4114 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 17 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | s.leberre and heurs |
| Vulnerable: |
Kaspersky Anti-Virus 2010 9.0.0.463 Kaspersky Anti-Virus 2010 |
| Not Vulnerable: | |
Discussion
Kaspersky Anti-Virus 'kl1.sys' Driver Local Privilege Escalation Vulnerability
Kaspersky Anti-Virus is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges and completely compromise the affected computer. Failed exploit attempts will result in a denial-of-service condition.
Kaspersky Anti-Virus 2010 9.0.0.463 is vulnerable; other versions may also be affected.
Kaspersky Anti-Virus is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges and completely compromise the affected computer. Failed exploit attempts will result in a denial-of-service condition.
Kaspersky Anti-Virus 2010 9.0.0.463 is vulnerable; other versions may also be affected.
Exploit / POC
Kaspersky Anti-Virus 'kl1.sys' Driver Local Privilege Escalation Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
Kaspersky Anti-Virus 'kl1.sys' Driver Local Privilege Escalation Vulnerability
Solution:
The vendor states that the issue was fixed on October 16, 2009 and that the fix was automatically distributed to vulnerable products.
Solution:
The vendor states that the issue was fixed on October 16, 2009 and that the fix was automatically distributed to vulnerable products.
References
Kaspersky Anti-Virus 'kl1.sys' Driver Local Privilege Escalation Vulnerability
References:
References: