|Date: (C)2009-11-30 (M)2017-08-18|| |
kl1.sys in Kaspersky Anti-Virus 2010 22.214.171.1243, and possibly other versions before 126.96.36.1996, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of service (system crash) via IOCTL requests using crafted kernel addresses that trigger memory corruption, possibly related to klavemu.kdl.
|CVSS Score: 4.9||Access Vector: LOCAL|
|Exploit Score: 3.9||Access Complexity: LOW|
|Impact Score: 6.9||Authentication: NONE|
| ||Confidentiality: NONE|
| ||Integrity: NONE|
| ||Availability: COMPLETE|