CVE-2009-3523
Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption,…
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- avast/avast antivirus home · avast/avast antivirus professional
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/36858Vendor Advisory
- http://www.avast.com/eng/avast-4-home_pro-revision-history.html
- http://www.ntinternals.org/ntiadv0904/ntiadv0904.htmlExploit
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6024
- http://secunia.com/advisories/36858Vendor Advisory
- http://www.avast.com/eng/avast-4-home_pro-revision-history.html
- http://www.ntinternals.org/ntiadv0904/ntiadv0904.htmlExploit
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6024
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.