7.2
CVE-2010-0705
- EPSS 0.93%
- Veröffentlicht 25.02.2010 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:16:41
- Erkennungen
Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Avast ≫ Avast Antivirus Home Edition windows Version <= 5.0.396.0
Avast ≫ Avast Antivirus Home Version 4.8.1169 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1195 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1201 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1227 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1229 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1282 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1290 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1296 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1335 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1351 Edition windows
Avast ≫ Avast Antivirus Home Version 4.8.1368.0 Edition windows
Avast ≫ Avast Antivirus Professional Edition windows Version <= 5.0.396.0
Avast ≫ Avast Antivirus Professional Version 4.8.1169 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1195 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1201 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1227 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1229 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1282 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1290 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1296 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1335 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1351 Edition windows
Avast ≫ Avast Antivirus Professional Version 4.8.1356.0
Avast ≫ Avast Antivirus Professional Version 4.8.1368.0 Edition windows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.93% | 0.559 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://forum.avast.com/index.php?topic=55484.0
http://osvdb.org/62510
http://secunia.com/advisories/38677
http://secunia.com/advisories/38689
http://www.securityfocus.com/archive/1/509710/100/0/threaded
http://www.securityfocus.com/bid/38363
http://www.securitytracker.com/id?1023644
http://www.trapkit.de/advisories/TKADV2010-003.txt
http://www.vupen.com/english/advisories/2010/0449