7.2
CVSSv2

CVE-2010-0705

Published: 25/02/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Aavmker4.sys in avast! 4.8 up to and including 4.8.1368.0 and 5.0 prior to 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

Vulnerable Product Search on Vulmon Subscribe to Product

avast avast antivirus home

avast avast antivirus home 4.8.1169

avast avast antivirus home 4.8.1195

avast avast antivirus home 4.8.1201

avast avast antivirus home 4.8.1227

avast avast antivirus home 4.8.1229

avast avast antivirus home 4.8.1282

avast avast antivirus home 4.8.1290

avast avast antivirus home 4.8.1296

avast avast antivirus home 4.8.1335

avast avast antivirus home 4.8.1351

avast avast antivirus home 4.8.1368.0

avast avast antivirus professional

avast avast antivirus professional 4.8.1169

avast avast antivirus professional 4.8.1195

avast avast antivirus professional 4.8.1201

avast avast antivirus professional 4.8.1227

avast avast antivirus professional 4.8.1229

avast avast antivirus professional 4.8.1282

avast avast antivirus professional 4.8.1290

avast avast antivirus professional 4.8.1296

avast avast antivirus professional 4.8.1335

avast avast antivirus professional 4.8.1351

avast avast antivirus professional 4.8.1356.0

avast avast antivirus professional 4.8.1368.0

Exploits

#!/usr/bin/python # avast! 47 aavmker4sys privilege escalation # wwwtrapkitde/advisories/TKADV2008-002txt # CVE-2008-1625 # Tested on WindXpSp2/Sp3 Dep ON # Matteo Memelli ryujin __A-T__ offensive-securitycom # wwwoffensive-securitycom # Spaghetti & Pwnsauce - 17/04/2010 # Tested on WinXPSP2/SP3 english | avast! 4710980 from c ...