CVE-2007-1880 - CERT CVE
ID CVE-2007-1880
Sažetak Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument," which results in a heap overflow.
Reference
CVSS
Base: 6.6
Impact: 10.0
Exploitability:2.7
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:L/AC:M/Au:S/C:C/I:C/A:C
Zadnje važnije ažuriranje 29-07-2017 - 01:31
Objavljeno 06-04-2007 - 00:19