VulnerabilityModified
CVE-2008-1625
Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.
MEDIUM 6.8EPSS 0.71%
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.
- CVSS 2.0
- 6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 0.71% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- avast/avast antivirus home · avast/avast antivirus professional
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29605Vendor Advisory
- http://www.avast.com/eng/avast-4-home_pro-revision-history.html
- http://www.securityfocus.com/archive/1/490321/100/0/threaded
- http://www.securityfocus.com/bid/28502
- http://www.securitytracker.com/id?1019732
- http://www.trapkit.de/advisories/TKADV2008-002.txt
- http://www.vupen.com/english/advisories/2008/1034/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41527
- http://secunia.com/advisories/29605Vendor Advisory
- http://www.avast.com/eng/avast-4-home_pro-revision-history.html
- http://www.securityfocus.com/archive/1/490321/100/0/threaded
- http://www.securityfocus.com/bid/28502
- http://www.securitytracker.com/id?1019732
- http://www.trapkit.de/advisories/TKADV2008-002.txt
- http://www.vupen.com/english/advisories/2008/1034/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41527
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.