6.9
CVSSv2

CVE-2009-3523

Published: 01/10/2009 Updated: 19/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

aavmKer4.sys in avast! Home and Professional for Windows prior to 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

Vulnerable Product Search on Vulmon Subscribe to Product

avast avast antivirus home 4.8.1227

avast avast antivirus home 4.7.827

avast avast antivirus professional 4.7.1043

avast avast antivirus professional 4.7.1098

avast avast antivirus professional 4.8.1201

avast avast antivirus professional 4.8.1227

avast avast antivirus professional 4.8.1296

avast avast antivirus home 4.7.1098

avast avast antivirus home 4.7.1043

avast avast antivirus home 4.8.1201

avast avast antivirus home 4.8.1229

avast avast antivirus professional 4.8.1169

avast avast antivirus professional 4.7.827

avast avast antivirus professional 4.8.1290

avast avast antivirus professional 4.8.1335

avast avast antivirus home 4.8.1169

avast avast antivirus home 4.7.844

avast avast antivirus home 4.8.1290

avast avast antivirus home 4.8.1335

avast avast antivirus professional 4.8.1229

avast avast antivirus professional 4.8.1282

avast avast antivirus home 4.8.1195

avast avast antivirus home 4.7.869

avast avast antivirus home 4.8.1282

avast avast antivirus home 4.8.1296

avast avast antivirus professional 4.8.1195

avast avast antivirus professional 4.7.844

avast avast antivirus professional

avast avast antivirus home

Exploits

#!/usr/bin/python # avast! 47 aavmker4sys privilege escalation # wwwtrapkitde/advisories/TKADV2008-002txt # CVE-2008-1625 # Tested on WindXpSp2/Sp3 Dep ON # Matteo Memelli ryujin __A-T__ offensive-securitycom # wwwoffensive-securitycom # Spaghetti & Pwnsauce - 17/04/2010 # Tested on WinXPSP2/SP3 english | avast! 4710980 from c ...