First published: Fri Nov 18 2005(Updated: )
Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3663 is considered a moderate severity vulnerability due to potential privilege escalation risks.
To fix CVE-2005-3663, ensure that the installation path for Kaspersky Anti-Virus 5.0 is correctly quoted to prevent untrusted file execution.
CVE-2005-3663 affects Kaspersky Anti-Virus 5.0 installed on Windows file servers.
Yes, local users may exploit CVE-2005-3663 to gain elevated privileges on systems with the vulnerable software.
A potential workaround for CVE-2005-3663 is to relocate any executable files that could be misused to a secure folder.