CVE-2009-3177
Unspecified vulnerability in Kaspersky Online Scanner 7.0 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, (1) "Kaspersky Online Antivirus Scanner 7.0 exploit (Linux)" and (2) "Kaspersky…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Kaspersky Online Scanner 7.0 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, (1) "Kaspersky Online Antivirus Scanner 7.0 exploit (Linux)" and (2) "Kaspersky Online Antivirus Scanner 7.0 exploit (Windows)." NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- kaspersky/kaspersky anti-virus scanner · kaspersky/kaspersky online scanner
- Source
- cve@mitre.org
References
- http://intevydis.com/vd-list.shtml
- http://secunia.com/advisories/36570Vendor Advisory
- http://www.securityfocus.com/bid/36243
- http://www.securitytracker.com/id?1022831
- http://intevydis.com/vd-list.shtml
- http://secunia.com/advisories/36570Vendor Advisory
- http://www.securityfocus.com/bid/36243
- http://www.securitytracker.com/id?1022831
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.