Vulnerability Name: | CVE-2008-6962 (CCN-46567) | ||||||||
Assigned: | 2008-11-12 | ||||||||
Published: | 2008-11-12 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-6962 Source: CCN Type: Avira Web site Avira Source: CCN Type: FrSIRT Security Advisory - Nov 12, 2008 Avira Products Driver Local Kernel Pointer Overwrite Vulnerability Source: CCN Type: OSVDB ID: 57004 Avira Antivir Multiple Products Crafted IOCTL Request Arbitrary Local Code Execution Source: BID Type: UNKNOWN 32269 Source: CCN Type: BID-32269 Multiple Avira Products Driver IOCTL Request Local Buffer Overflow Vulnerabilty Source: VUPEN Type: Vendor Advisory ADV-2008-3130 Source: MISC Type: Vendor Advisory http://www.vupen.com/english/VUPEN-Security-Advisory-20081112.txt Source: XF Type: UNKNOWN avira-ioctl-privilege-escalation(46567) Source: XF Type: UNKNOWN avira-ioctl-privilege-escalation(46567) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |