CVE-2005-3663: High severity Kaspersky Lab Kaspersky Anti-virus vulnerability
Published Nov 18, 2005
·Updated
Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.
Affected Software
1 affected component
Kaspersky Lab Kaspersky Anti-virus=5.0
Event History
Nov 18, 2005
CVE Published
06:04 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3663?
CVE-2005-3663 is considered a moderate severity vulnerability due to potential privilege escalation risks.
2
How do I fix CVE-2005-3663?
To fix CVE-2005-3663, ensure that the installation path for Kaspersky Anti-Virus 5.0 is correctly quoted to prevent untrusted file execution.
3
What systems are affected by CVE-2005-3663?
CVE-2005-3663 affects Kaspersky Anti-Virus 5.0 installed on Windows file servers.
4
Can local users exploit CVE-2005-3663?
Yes, local users may exploit CVE-2005-3663 to gain elevated privileges on systems with the vulnerable software.
5
Is there a workaround for CVE-2005-3663?
A potential workaround for CVE-2005-3663 is to relocate any executable files that could be misused to a secure folder.