Vulnerability CVE-2010-5163


Published: 2012-08-25

Description:
** DISPUTED ** Race condition in Kaspersky Internet Security 2010 9.0.0.736 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

Vendor: Kaspersky
Product: Kaspersky internet security 2010 
Version: 9.0.0.736;

CVSS2 => (AV:L/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.2/10
10/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://www.theregister.co.uk/2010/05/07/argument_switch_av_bypass/
http://www.securityfocus.com/bid/39924
http://www.osvdb.org/67660
http://www.f-secure.com/weblog/archives/00001949.html
http://matousec.com/info/articles/khobe-8.0-earthquake-for-windows-desktop-security-software.php
http://matousec.com/info/advisories/khobe-8.0-earthquake-for-windows-desktop-security-software.php
http://countermeasures.trendmicro.eu/you-just-cant-trust-a-drunk/
http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0066.html
http://archives.neohapsis.com/archives/bugtraq/2010-05/0026.html

Related CVE
CVE-2018-6291
WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
CVE-2018-6290
Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
CVE-2018-6289
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
CVE-2018-6288
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
CVE-2017-12823
Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation.
CVE-2017-12817
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
CVE-2017-12816
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC.
CVE-2017-9811
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate t...

Copyright 2019, cxsecurity.com

 

Back to Top