Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the NtCreateSection kernel SSDT hook or (2) cause a denial of service (avp.exe service outage) via the NtLoadDriver kernel SSDT hook. NOTE: this issue may partially overlap CVE-2006-3074.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kaspersky Internet Security SSDT钩子多个本地拒绝服务漏洞
Vulnerability Description
Kaspersky Internet Security套件是一套完整的解决方案,用于保护计算机抵御几乎所有来自互联网的主要的威胁。 Kaspersky Internet Security的驱动在HOOK系统函数的实现上存在漏洞,本地攻击者可能利用此漏洞导致系统崩溃。 Kaspersky Internet Security hook了很多SSDT中的函数,其中的NtCreateKey、NtCreateProcess、NtCreateProcessEx、NtCreateSection、NtCreateSymb
CVSS Information
N/A
Vulnerability Type
N/A