|Date: (C)2009-11-30 (M)2017-08-18|
|CVSS Score: 4.9||Access Vector: LOCAL|
|Exploitability Subscore: 3.9||Access Complexity: LOW|
|Impact Subscore: 6.9||Authentication: NONE|
| ||Confidentiality: NONE|
| ||Integrity: NONE|
| ||Availability: COMPLETE|
kl1.sys in Kaspersky Anti-Virus 2010 126.96.36.1993, and possibly other versions before 188.8.131.526, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of service (system crash) via IOCTL requests using crafted kernel addresses that trigger memory corruption, possibly related to klavemu.kdl.