Vulnerability Name: | CVE-2007-5086 (CCN-34875) | ||||||||
Assigned: | 2007-06-15 | ||||||||
Published: | 2007-06-15 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4) NtOpenThread, (5) NtTerminateProcess, (6) NtUserFindWindowEx, and (7) NtUserBuildHwndList kernel SSDT hooks in kylif.sys; the (8) NtDuplicateObject (DuplicateHandle) kernel SSDT hook; and possibly other kernel SSDT hooks. Note: the NtCreateSection vector is covered by CVE-2007-5043.1. Note: the vendor disputes that the DuplicateHandle vector is a vulnerability in their code, stating that "it is not an error in our code, but an obscure method for manipulating standard Windows routines to circumvent our self-defense mechanisms." | ||||||||
CVSS v3 Severity: | 6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P) 1.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-5086 Source: OSVDB Type: UNKNOWN 37990 Source: CCN Type: SA26887 Kaspersky AntiVirus klif.sys Hooked Functions Denial of Service Source: SECUNIA Type: Vendor Advisory 26887 Source: CCN Type: Kaspersky Anti-Virus Web site Kaspersky Lab: Antivirus software Source: CCN Type: Kapersky Web site Product Updates Source: CCN Type: Kaspersky Web site Faulty data processing in klif.sys driver Source: CONFIRM Type: UNKNOWN http://www.kaspersky.com/technews?id=203038706 Source: CCN Type: MatouSec Transparent Security Advisory 2007-06-15.01 Kaspersky Multiple insufficient argument validation of hooked SSDT function Vulnerability Source: CCN Type: OSVDB ID: 37990 Kaspersky Multiple Products Multiple SSDT Functions Local Privilege Escalation Source: CCN Type: Rootkit Web site Haxdoors of the Kaspersky Antivirus 6/7 Source: MISC Type: Exploit http://www.rootkit.com/newsread.php?newsid=778 Source: VUPEN Type: UNKNOWN ADV-2007-3259 Source: XF Type: UNKNOWN kaspersky-multiple-klif-dos(34875) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |