Vulnerability Name:

CVE-2007-1879 (CCN-33464)

Assigned:2007-04-04
Published:2007-04-04
Updated:2017-07-29
Summary:The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anonymous FTP session that invokes the PUT command.
Note: this issue might be related to CVE-2007-1112.
CVSS v3 Severity:4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2007-1112

Source: MITRE
Type: CNA
CVE-2007-1879

Source: IDEFENSE
Type: UNKNOWN
20070404 Kaspersky AntiVirus SysInfo ActiveX Control Information Disclosure Vulnerability

Source: CCN
Type: SA24778
Kaspersky Products Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
24778

Source: CCN
Type: SECTRACK ID: 1017871
Kaspersky Anti-Virus `AxKLSysInfo.dll` ActiveX Control Lets Remote Users View Files

Source: CCN
Type: SECTRACK ID: 1017884
Kaspersky Anti-Virus ActiveX Controls Let Remote Users View and Delete Files

Source: CCN
Type: SECTRACK ID: 1017885
Kaspersky Internet Security ActiveX Controls Let Remote Users View and Delete Files

Source: CCN
Type: Kaspersky Anti-Virus and Internet Security Web site
Kaspersky Anti-Virus 6.0, Kaspersky Internet Security 6.0 - 5 vulnerabilities fixed in Maintenance Pack 2.0 build 6.0.2.614

Source: CONFIRM
Type: Vendor Advisory
http://www.kaspersky.com/technews?id=203038694

Source: CCN
Type: OSVDB ID: 33849
Kaspersky Multiple Products AXKLPROD60Lib.KAV60Info ActiveX Multiple Method Arbitrary File Manipulation

Source: CCN
Type: OSVDB ID: 33850
Kaspersky Multiple Products AXKLSYSINFOLib.SysInfo ActiveX Multiple Method Arbitrary File Manipulation

Source: CCN
Type: OSVDB ID: 34328
Kaspersky Multiple Products KL.SysInfo ActiveX (AxKLSysInfo.dll) StartUploading Function Arbitrary File Access

Source: BID
Type: UNKNOWN
23325

Source: CCN
Type: BID-23325
Kaspersky AntiVirus SysInfo ActiveX Control Arbitrary File Exfiltration Vulnerability

Source: CCN
Type: BID-23345
Kaspersky AntiVirus Prod60 ActiveX Control Arbitrary File Exfiltration Vulnerability

Source: SECTRACK
Type: UNKNOWN
1017871

Source: VUPEN
Type: UNKNOWN
ADV-2007-1268

Source: XF
Type: UNKNOWN
kaspersky-multiple-unsafe-info-disclosure(33464)

Source: XF
Type: UNKNOWN
kaspersky-startuploading-info-disclosure(33464)

Source: CCN
Type: iDefense Labs PUBLIC ADVISORY: 04.04.07
Kaspersky AntiVirus SysInfo ActiveX Control Information Disclosure Vulnerability

Source: CCN
Type: ZDI-07-014
Kaspersky Anti-Virus ActiveX Control Unsafe Method Exposure Vulnerablity

Vulnerable Configuration:Configuration 1:
  • cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0:*:windows_workstation:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_internet_security:*:*:*:*:*:*:*:* (Version <= 6.0.1.411)

  • Configuration CCN 1:
  • cpe:/a:kaspersky:kaspersky_anti-virus:6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    kaspersky_lab kaspersky anti-virus 6.0
    kaspersky_lab kaspersky internet security *
    kaspersky kaspersky anti-virus 6.0