5
CVSSv2

CVE-2006-3074

Published: 19/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.

Vulnerable Product Search on Vulmon Subscribe to Product

kaspersky kaspersky internet security 6.0

kaspersky kaspersky anti-virus 6.0

kaspersky kaspersky internet security 7.0

kaspersky kaspersky anti-virus 7.0

kaspersky kaspersky_anti-virus 6.0

Exploits

source: wwwsecurityfocuscom/bid/24491/info Kaspersky Internet Security 6 is prone to multiple local vulnerabilities Exploiting these vulnerabilities allows local attackers to crash affected computers, denying service to legitimate users Attackers might also be able to gain elevated privileges by executing arbitrary machine code in the ...