First published: Fri Apr 06 2007(Updated: )
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | =6.0 | |
Kaspersky Internet Security 2010 | =6.0-maintenance_pack_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1112 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-1112, users should update to the latest version of Kaspersky Anti-Virus or Kaspersky Internet Security that addresses this vulnerability.
The affected products of CVE-2007-1112 include Kaspersky Anti-Virus 6.0 and Kaspersky Internet Security 6.0 with specific versions.
Attackers exploiting CVE-2007-1112 can potentially download or delete arbitrary files on the victim's system.
CVE-2007-1112 was disclosed in February 2007, highlighting significant risks associated with the affected Kaspersky products.