Vulnerability CVE-2007-1112


Published: 2007-04-05   Modified: 2012-02-12

Description:
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Kaspersky lab -> Kaspersky anti-virus 
Kaspersky lab -> Kaspersky internet security 

 References:
http://www.kaspersky.com/technews?id=203038694
http://www.securityfocus.com/archive/1/464882/100/0/threaded
http://www.securityfocus.com/bid/23345
http://www.securitytracker.com/id?1017884
http://www.securitytracker.com/id?1017885
http://www.vupen.com/english/advisories/2007/1268
http://www.zerodayinitiative.com/advisories/ZDI-07-014.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/33464

Copyright 2024, cxsecurity.com

 

Back to Top