7.2
CVSSv2

CVE-2010-0705

Published: 25/02/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Aavmker4.sys in avast! 4.8 up to and including 4.8.1368.0 and 5.0 prior to 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

Vulnerable Product Search on Vulmon Subscribe to Product

avast avast_antivirus_home 4.8.1227

avast avast_antivirus_home 4.8.1201

avast avast_antivirus_professional 4.8.1356.0

avast avast_antivirus_professional 4.8.1368.0

avast avast_antivirus_home

avast avast_antivirus_professional

avast avast_antivirus_professional 4.8.1296

avast avast_antivirus_professional 4.8.1290

avast avast_antivirus_home 4.8.1282

avast avast_antivirus_home 4.8.1229

avast avast_antivirus_home 4.8.1368.0

avast avast_antivirus_professional 4.8.1169

avast avast_antivirus_home 4.8.1195

avast avast_antivirus_home 4.8.1169

avast avast_antivirus_home 4.8.1351

avast avast_antivirus_home 4.8.1335

avast avast_antivirus_professional 4.8.1282

avast avast_antivirus_professional 4.8.1201

avast avast_antivirus_professional 4.8.1227

avast avast_antivirus_professional 4.8.1351

avast avast_antivirus_professional 4.8.1335

avast avast_antivirus_home 4.8.1296

avast avast_antivirus_home 4.8.1290

avast avast_antivirus_professional 4.8.1195

avast avast_antivirus_professional 4.8.1229

Exploits

#!/usr/bin/python # avast! 47 aavmker4sys privilege escalation # wwwtrapkitde/advisories/TKADV2008-002txt # CVE-2008-1625 # Tested on WindXpSp2/Sp3 Dep ON # Matteo Memelli ryujin __A-T__ offensive-securitycom # wwwoffensive-securitycom # Spaghetti & Pwnsauce - 17/04/2010 # Tested on WinXPSP2/SP3 english | avast! 4710980 from c ...