Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2003-1443

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kaspersky Antivirus (KAV) 4.0.9.0版本不能发现文件名中带有MS-DOS设备名文件的病毒,本地用户可以借助该漏洞绕过病毒保护,正如使用aux.vbs和aux.com。

AI Predicted 4.3 Difficulty: Moderate EPSS 0.48% · P40
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2003-1443

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Kaspersky Antivirus (KAV)病毒保护绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Kaspersky Antivirus (KAV) 4.0.9.0版本不能发现文件名中带有MS-DOS设备名文件的病毒,本地用户可以借助该漏洞绕过病毒保护,正如使用aux.vbs和aux.com。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2003-1443

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-1443

登录查看更多情报信息。

Mailing List Discussions for CVE-2003-1443 (1)

Same Patch Batch · n/a · 2007-10-23 · 66 CVEs total

CVE-2003-1438 BEA Systems WebLogic Server和Express会话共享漏洞
CVE-2003-1458 ttCMS / ttForum Profile.php SQL注入漏洞
CVE-2003-1457 Auerswald COMsuite CTI应用程序弱默认密码漏洞
CVE-2003-1456 Mike Bobbitt album.pl远程任意命令执行漏洞
CVE-2003-1445 RARLAB FAR文件管理器缓冲区溢出漏洞
CVE-2003-1444 Kaspersky Antivirus (KAV)漏洞
CVE-2003-1442 HM220dp ADSL modem WEB管理接口不安全漏洞
CVE-2003-1441 Posadis DNS请求问题区远程拒绝服务漏洞
CVE-2003-1440 SpamProbe远程拒绝服务漏洞
CVE-2003-1439 SILC Server SSH2本地内存中密码泄露漏洞
CVE-2003-1446 Rogue变量扩展缓冲区溢出漏洞
CVE-2003-1437 BEA WebLogic密钥库清除文本密码存储漏洞
CVE-2003-1436 Nukebrowser远程包含漏洞
CVE-2003-1435 PHP-Nuke modules.php远程可获取加密后口令漏洞
CVE-2003-1434 login_ldap模块未授权访问漏洞
CVE-2003-1433 Epic Games Unreal Engine多用户拒绝服务攻击漏洞
CVE-2003-1432 Epic Games Unreal Engine内存消耗拒绝服务攻击漏洞
CVE-2003-1431 Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞
CVE-2003-1430 Epic Games Unreal Engine Unreal URL目录遍历漏洞
CVE-2003-1429 Proxomitron Naoko缓冲区溢出漏洞

Showing top 20 of 66 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2003-1443

No comments yet


Leave a comment