Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x8h-p499-xj9p

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability.

Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability.

EPSS

Процентиль: 27%
0.00097
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
nvd
около 9 лет назад

Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability.

fstec
почти 10 лет назад

Множественные уязвимости средства антивирусной защиты Kaspersky Total Security, позволяющие нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 27%
0.00097
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200