6.8
CVSSv2

CVE-2009-4452

Published: 29/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 10 | Exploitability Score: 3.1
VMScore: 685
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse.

Vulnerable Product Search on Vulmon Subscribe to Product

kaspersky lab kaspersky anti-virus 2010 9.0.0.463

kaspersky lab kaspersky anti-virus 5.0.712

kaspersky lab kaspersky internet security 2010 9.0.0.463

kaspersky lab kaspersky anti-virus personal 5.0.228

kaspersky lab kaspersky anti-virus personal 5.0.325

kaspersky lab kaspersky internet security 7.0.1.325

kaspersky lab kaspersky internet security 2009 8.0.0.506

kaspersky lab kaspersky anti-virus personal 5.0

kaspersky lab kaspersky anti-virus personal 5.0.227

kaspersky lab kaspersky anti-virus 7.0.1.325

kaspersky lab kaspersky anti-virus 2009 8.0.0.454

kaspersky lab kaspersky anti-virus 6.0.3.837

Exploits

ShineShadow Security Report 16122009-15 TITLE Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability BACKGROUND Due to its high level of professionalism and dedication, Kaspersky Lab has become a market leader in the development of antivirus protection The company’s main product, Kaspersky Anti-Virus, regularly receives to ...