First published: Mon Sep 19 2005(Updated: )
The v3flt2k.sys driver in AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, V3Net for Windows Server 6.0 Build 6.0.0.383 does not properly validate the source of the DeviceIoControl commands, which allows remote attackers to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ahnlab V3 Virusblock 2005 | =6.0.0.383 | |
Ahnlab V3net | =6.0.0.383 | |
AhnLab V3Pro 2004 | =6.0.0.383 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2986 is classified as a high-severity vulnerability due to its potential to allow remote privilege escalation.
To fix CVE-2005-2986, users should update to the latest version of AhnLab V3Pro, V3 VirusBlock, or V3Net that addresses the vulnerability.
CVE-2005-2986 affects AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, and V3Net for Windows Server 6.0 Build 6.0.0.383.
CVE-2005-2986 is a privilege escalation vulnerability due to improper validation of DeviceIoControl commands.
CVE-2005-2986 can be exploited by remote attackers who can send specially crafted DeviceIoControl commands.