Vulnerability CVE-2010-5075


Published: 2014-12-27   Modified: 2014-12-28

Description:
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.

Type:

CWE-189

(Numeric Errors)

Vendor: Avast!
Product: Avast! internet security 
Version: 5.0;

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
https://web.archive.org/web/20120228033302/http://www.x90c.org/advisories/avast_internet_security_5.0_memory_corruption_advisory.txt
http://x90c.blogspot.com/2011/12/bid-42148-my-avast-kernel-driver-0day_01.html
http://x90c.blogspot.com/2011/11/avast-internet-security-aswfwsys-ioctl.html
http://www.securityfocus.com/bid/42148

Copyright 2019, cxsecurity.com

 

Back to Top