Vulnerabilities > CVE-2007-1880 - Local Heap Overflow vulnerability in Kaspersky Internet Security Suite Klif.SYS Driver

047910
CVSS 6.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
kaspersky-lab
nessus

Summary

Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument," which results in a heap overflow. The vendor has addressed this vulnerability within Maintenance Pack 2. More information is available from the following link: http://www.kaspersky.com/technews?id=203038693

Nessus

NASL familyWindows
NASL idKASPERSKY_AV6_MULT_VULNS.NASL
descriptionThe version of the Kaspersky antivirus product installed on the remote host may be affected by buffer overflow, privilege escalation, and information disclosure vulnerabilities, depending on the actual product installed.
last seen2020-06-01
modified2020-06-02
plugin id25021
published2007-04-10
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/25021
titleKaspersky Anti-Virus < 6.0.2.614 Multiple Vulnerabilities