CVE-2009-1824
The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet Security 9.4.3202.9 and earlier, ArcaVir 2009 System Protection 9.4.3203.9 and earlier, and ArcaBit 2009 Home Protection 9.4.3204.9…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet Security 9.4.3202.9 and earlier, ArcaVir 2009 System Protection 9.4.3203.9 and earlier, and ArcaBit 2009 Home Protection 9.4.3204.9 and earlier, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\ps_drv containing arbitrary kernel addresses, as demonstrated using the (1) 0x2A7B802B and possibly (2) 0x2A7B8004 and (3) 0x2A7B802F IOCTLs.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- arcabit/arcavir 2009 antivirus protection · arcabit/arcavir 2009 home protection · arcabit/arcavir 2009 internet security · arcabit/arcavir 2009 system protection
- Source
- cve@mitre.org
References
- http://ntinternals.org/ntiadv0814/PsDrv_Exp.zipExploit
- http://ntinternals.org/ntiadv0814/ntiadv0814.htmlExploit
- http://secunia.com/advisories/35260Vendor Advisory
- http://www.securityfocus.com/bid/35100Exploit
- http://www.vupen.com/english/advisories/2009/1428Vendor Advisory
- https://www.exploit-db.com/exploits/8782
- http://ntinternals.org/ntiadv0814/PsDrv_Exp.zipExploit
- http://ntinternals.org/ntiadv0814/ntiadv0814.htmlExploit
- http://secunia.com/advisories/35260Vendor Advisory
- http://www.securityfocus.com/bid/35100Exploit
- http://www.vupen.com/english/advisories/2009/1428Vendor Advisory
- https://www.exploit-db.com/exploits/8782
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.