7.2

CVE-2006-4926

Exploit

The NDIS-TDI Hooking Engine, as used in the (1) KLICK (KLICK.SYS) and (2) KLIN (KLIN.SYS) device drivers 2.0.0.281 for in Kaspersky Labs Anti-Virus 6.0.0.303 and other Anti-Virus and Internet Security products, allows local users to execute arbitrary code via crafted Irp structure with invalid addresses in the 0x80052110 IOCTL.

Data is provided by the National Vulnerability Database (NVD)
Kaspersky LabKaspersky Anti-virus Version5.0 Editionwindows_workstations
Kaspersky LabKaspersky Anti-virus Version6.0 Editionworkstations
Kaspersky LabKaspersky Internet Security Version6.0 Updatemaintenance_pack_2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.31% 0.534
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C