6.8
CVSSv2

CVE-2008-1625

Published: 02/04/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 10 | Exploitability Score: 3.1
VMScore: 685
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.

Vulnerable Product Search on Vulmon Subscribe to Product

avast avast antivirus home 4.7.1043

avast avast antivirus home 4.7.1098

avast avast antivirus home 4.7.827

avast avast antivirus home 4.7.844

avast avast antivirus home 4.7.869

avast avast antivirus professional 4.7.844

avast avast antivirus professional 4.7.1043

avast avast antivirus professional 4.7.1098

avast avast antivirus professional 4.7.827

Exploits

#!/usr/bin/python # avast! 47 aavmker4sys privilege escalation # wwwtrapkitde/advisories/TKADV2008-002txt # CVE-2008-1625 # Tested on WindXpSp2/Sp3 Dep ON # Matteo Memelli ryujin __A-T__ offensive-securitycom # wwwoffensive-securitycom # Spaghetti & Pwnsauce - 17/04/2010 # Tested on WinXPSP2/SP3 english | avast! 4710980 from c ...
Avast! version 47 aavmker4sys local privilege escalation vulnerability ...