CVE-2007-1112
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.88% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- kaspersky lab/kaspersky anti-virus · kaspersky lab/kaspersky internet security
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24778Patch, Vendor Advisory
- http://www.kaspersky.com/technews?id=203038694Patch
- http://www.securityfocus.com/archive/1/464882/100/0/threaded
- http://www.securityfocus.com/bid/23345
- http://www.securitytracker.com/id?1017884
- http://www.securitytracker.com/id?1017885
- http://www.vupen.com/english/advisories/2007/1268
- http://www.zerodayinitiative.com/advisories/ZDI-07-014.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33464
- http://secunia.com/advisories/24778Patch, Vendor Advisory
- http://www.kaspersky.com/technews?id=203038694Patch
- http://www.securityfocus.com/archive/1/464882/100/0/threaded
- http://www.securityfocus.com/bid/23345
- http://www.securitytracker.com/id?1017884
- http://www.securitytracker.com/id?1017885
- http://www.vupen.com/english/advisories/2007/1268
- http://www.zerodayinitiative.com/advisories/ZDI-07-014.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33464
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.