Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability
BID:37354
Info
Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability
| Bugtraq ID: | 37354 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 16 2009 12:00AM |
| Updated: | Dec 16 2009 07:33PM |
| Credit: | Maxim A. Kulakov |
| Vulnerable: |
Kaspersky Labs Anti-Virus for Windows Workstations 6.0.2.837 Kaspersky Internet Security 6.0 Kaspersky Internet Security 2010 9.0.0.463 Kaspersky Internet Security 2010 9.0.0.459 Kaspersky Internet Security 2010 Kaspersky Anti-Virus for Windows Workstation 6.0 Kaspersky Anti-Virus for Windows Server 6.0 Kaspersky Anti-Virus 2008 8.0.0.0 Kaspersky Anti-Virus 5.0.712 Kaspersky Anti-Virus 7.0.1.325 Kaspersky Anti-Virus 7.0 Kaspersky Anti-Virus 6.0.2.678 Kaspersky Anti-Virus 2010 Kaspersky Anti-Virus 2008 |
| Not Vulnerable: |
Kaspersky Internet Security 2010 9.0.0.736 Kaspersky Internet Security 6.0.1.411 Kaspersky Anti-Virus Windows Workstations 6.0.4.1212 Kaspersky Anti-Virus Windows File Servers 6.0.4.1212 Kaspersky Anti-Virus 2010 9.0.0.736 |
Discussion
Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability
Multiple Kaspersky products are prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges and completely compromise the affected computer. Failed exploit attempts will result in a denial-of-service condition.
Multiple Kaspersky products are prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges and completely compromise the affected computer. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability
An attacker can use readily available command-line utilities to exploit this issue.
An attacker can use readily available command-line utilities to exploit this issue.
Solution / Fix
Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability
References:
References:
- Vendor Homepage (Kaspersky Labs)
- Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability ([email protected] (Maxim A. Kulakov))