7.5

CVE-2005-2986

The v3flt2k.sys driver in AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, V3Net for Windows Server 6.0 Build 6.0.0.383 does not properly validate the source of the DeviceIoControl commands, which allows remote attackers to gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ahnlab ≫ V3 Virusblock 2005 Version 6.0.0.383
Ahnlab ≫ V3net Version 6.0.0.383 Edition win_server
Ahnlab ≫ V3pro 2004 Version 6.0.0.383
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.39% 0.818
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/14847
http://info.ahnlab.com/english/advisory/01.html
Patch
Vendor Advisory
http://marc.info/?l=bugtraq&m=112680062609377&w=2
http://secunia.com/advisories/15674/
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/22297