Description
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.
Affected products
- Kaspersky / Kaspersky Anti-Virus6.0 – 6.0
- Kaspersky / Kaspersky Anti-Virus7.0 – 7.0
- Kaspersky / Kaspersky Internet Security6.0 – 6.0
- Kaspersky / Kaspersky Internet Security7.0 – 7.0
Exploits & proofs of concept
- exploit-dbKaspersky Internet Security 6.0 - SSDT Hooks Multiple Local Vulnerabilitiesby Matousec Transparent security
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/27104
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/34875
- MISChttp://www.securityfocus.com/bid/18341
- MISChttp://www.securitytracker.com/id?1018257
- MISChttp://uninformed.org/index.cgi?v=4&a=4&p=4
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/2145
- MISChttp://www.securityfocus.com/bid/24491
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/2333
- MISChttp://www.kaspersky.com/technews?id=203038695
- VENDOR_ADVISORYhttp://secunia.com/advisories/25603
- MISChttp://www.rootkit.com/board.php?did=edge726&closed=0&lastx=15
- MISChttp://www.securityfocus.com/archive/1/471453/100/0/threaded
- VENDOR_ADVISORYhttp://www.matousec.com/info/advisories/Kaspersky-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php
- VENDOR_ADVISORYhttp://secunia.com/advisories/20629
- MISChttp://uninformed.org/index.cgi?v=4&a=4&p=7
- MISChttp://www.rootkit.com/newsread.php?newsid=726
Updated 15m ago · 8 sources