6.9

CVE-2009-3523

Exploit
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Avast ≫ Avast Antivirus Home Edition windows Version <= 4.8.1351
Avast ≫ Avast Antivirus Home Version 4.7.827 Edition windows
Avast ≫ Avast Antivirus Home Version 4.7.844 Edition windows
Avast ≫ Avast Antivirus Home Version 4.7.869 Edition windows
Avast ≫ Avast Antivirus Home Version 4.7.1043 Edition windows
Avast ≫ Avast Antivirus Home Version 4.7.1098 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1169 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1195 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1201 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1227 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1229 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1282 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1290 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1296 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1335 Edition windows
Avast ≫ Avast Antivirus Professional Edition windows Version <= 4.8.1351
Avast ≫ Avast Antivirus Professional Version 4.7.827 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.7.844 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.7.1043 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.7.1098 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1169 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1195 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1201 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1227 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1229 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1282 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1290 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1296 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1335 Edition windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.511
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.avast.com/eng/avast-4-home_pro-revision-history.html
http://secunia.com/advisories/36858
Vendor Advisory
http://www.ntinternals.org/ntiadv0904/ntiadv0904.html
Exploit
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6024