6.9

CVE-2009-3523

Exploit

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

Data is provided by the National Vulnerability Database (NVD)
AvastAvast Antivirus Home Editionwindows Version <= 4.8.1351
AvastAvast Antivirus Home Version4.7.827 Editionwindows
AvastAvast Antivirus Home Version4.7.844 Editionwindows
AvastAvast Antivirus Home Version4.7.869 Editionwindows
AvastAvast Antivirus Home Version4.7.1043 Editionwindows
AvastAvast Antivirus Home Version4.7.1098 Editionwindows
AvastAvast Antivirus Home Version4.8.1169 Editionwindows
AvastAvast Antivirus Home Version4.8.1195 Editionwindows
AvastAvast Antivirus Home Version4.8.1201 Editionwindows
AvastAvast Antivirus Home Version4.8.1227 Editionwindows
AvastAvast Antivirus Home Version4.8.1229 Editionwindows
AvastAvast Antivirus Home Version4.8.1282 Editionwindows
AvastAvast Antivirus Home Version4.8.1290 Editionwindows
AvastAvast Antivirus Home Version4.8.1296 Editionwindows
AvastAvast Antivirus Home Version4.8.1335 Editionwindows
AvastAvast Antivirus Professional Editionwindows Version <= 4.8.1351
AvastAvast Antivirus Professional Version4.7.827 Editionwindows
AvastAvast Antivirus Professional Version4.7.844 Editionwindows
AvastAvast Antivirus Professional Version4.7.1043 Editionwindows
AvastAvast Antivirus Professional Version4.7.1098 Editionwindows
AvastAvast Antivirus Professional Version4.8.1169 Editionwindows
AvastAvast Antivirus Professional Version4.8.1195 Editionwindows
AvastAvast Antivirus Professional Version4.8.1201 Editionwindows
AvastAvast Antivirus Professional Version4.8.1227 Editionwindows
AvastAvast Antivirus Professional Version4.8.1229 Editionwindows
AvastAvast Antivirus Professional Version4.8.1282 Editionwindows
AvastAvast Antivirus Professional Version4.8.1290 Editionwindows
AvastAvast Antivirus Professional Version4.8.1296 Editionwindows
AvastAvast Antivirus Professional Version4.8.1335 Editionwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.333
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.