Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kaspersky Anti-Virus klif.sys 拒绝服务漏洞
Vulnerability Description
Kaspersky Anti-Virus 6.0.0.300及之前版本, Internet Security 6.0.0.300及之前版本, 以及Internet Security Suite 5.0及之前版本中的klif.sys未对某些挂钩的系统调用进行验证,可以使本地用户引起拒绝服务(重新启动)。
CVSS Information
N/A
Vulnerability Type
N/A