5.5

CVE-2016-4307

Exploit
A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violation in KL1 kernel driver resulting in local system denial of service. An attacker can run a program from user-mode to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaspersky ≫ Internet Security Version 16.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.393
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.securitytracker.com/id/1036702
http://www.securitytracker.com/id/1036703
http://securitytracker.com/id/1036702
Third Party Advisory
VDB Entry
http://www.talosintelligence.com/reports/TALOS-2016-0169/
Third Party Advisory
Exploit
VDB Entry
Technical Description