Vulnerability Name:

CVE-2009-4452 (CCN-54875)

Assigned:2009-12-16
Published:2009-12-16
Updated:2018-10-10
Summary:Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
5.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: BugTraq Mailing List, Wed Dec 16 2009
Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability

Source: MITRE
Type: CNA
CVE-2009-4452

Source: CCN
Type: SA37398
Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability

Source: SECUNIA
Type: Vendor Advisory
37398

Source: CCN
Type: SA37730
Kaspersky Products Insecure Default Directory Permissions

Source: SECUNIA
Type: Vendor Advisory
37730

Source: CCN
Type: SECTRACK ID: 1023366
Kaspersky Anti-Virus Unsafe Access Control Configuration for BASES Folder Lets Local Users Gain Elevated Privileges

Source: CCN
Type: SECTRACK ID: 1023367
Kaspersky Internet Security Unsafe Access Control Configuration for BASES Folder Lets Local Users Gain Elevated Privileges

Source: CCN
Type: Kaspersky Web site
Kaspersky

Source: EXPLOIT-DB
Type: Exploit
10484

Source: CCN
Type: OSVDB ID: 61135
Kaspersky Multiple Products Application Data\Kaspersky Lab\AVP9\ Directory Permission Weakness Local Privilege Escalation

Source: BUGTRAQ
Type: UNKNOWN
20091216 Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability

Source: CCN
Type: BID-37354
Kaspersky Products 'Every One' Group Insecure Permissions Local Privilege Escalation Vulnerability

Source: SECTRACK
Type: UNKNOWN
1023366

Source: SECTRACK
Type: UNKNOWN
1023367

Source: VUPEN
Type: Vendor Advisory
ADV-2009-3573

Source: XF
Type: UNKNOWN
kaspersky-vlns-priv-escalation(54875)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:kaspersky_lab:kaspersky_anti-virus:5.0.712:*:windows_workstations:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0.3.837:*:windows_file_servers:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0.3.837:*:windows_workstation:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus:7.0.1.325:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus_2009:8.0.0.454:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus_2010:9.0.0.463:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus_personal:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus_personal:5.0.227:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus_personal:5.0.228:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_anti-virus_personal:5.0.325:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_internet_security:7.0.1.325:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_internet_security_2009:8.0.0.506:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky_lab:kaspersky_internet_security_2010:9.0.0.463:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:kaspersky:kaspersky_anti-virus:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:kaspersky:kaspersky_internet_security_2010:9.0.0.736:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    kaspersky_lab kaspersky anti-virus 5.0.712
    kaspersky_lab kaspersky anti-virus 6.0.3.837
    kaspersky_lab kaspersky anti-virus 6.0.3.837
    kaspersky_lab kaspersky anti-virus 7.0.1.325
    kaspersky_lab kaspersky anti-virus 2009 8.0.0.454
    kaspersky_lab kaspersky anti-virus 2010 9.0.0.463
    kaspersky_lab kaspersky anti-virus personal 5.0
    kaspersky_lab kaspersky anti-virus personal 5.0.227
    kaspersky_lab kaspersky anti-virus personal 5.0.228
    kaspersky_lab kaspersky anti-virus personal 5.0.325
    kaspersky_lab kaspersky internet security 7.0.1.325
    kaspersky_lab kaspersky internet security 2009 8.0.0.506
    kaspersky_lab kaspersky internet security 2010 9.0.0.463
    kaspersky kaspersky anti-virus 6.0
    kaspersky kaspersky internet security 2010 9.0.0.736