Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4306

Опубликовано: 06 янв. 2017
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kaspersky:total_security:16.0.0.614:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00097
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability.

fstec
почти 10 лет назад

Множественные уязвимости средства антивирусной защиты Kaspersky Total Security, позволяющие нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 27%
0.00097
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200