Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq8r-7hph-pwj2

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 16 лет назад

Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-20