CVE-2007-1112: Critical severity Kaspersky Lab Kaspersky Anti-virus vulnerability
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1112?
CVE-2007-1112 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2007-1112?
To fix CVE-2007-1112, users should update to the latest version of Kaspersky Anti-Virus or Kaspersky Internet Security that addresses this vulnerability.
What are the affected products of CVE-2007-1112?
The affected products of CVE-2007-1112 include Kaspersky Anti-Virus 6.0 and Kaspersky Internet Security 6.0 with specific versions.
What can attackers do exploiting CVE-2007-1112?
Attackers exploiting CVE-2007-1112 can potentially download or delete arbitrary files on the victim's system.
When was CVE-2007-1112 disclosed?
CVE-2007-1112 was disclosed in February 2007, highlighting significant risks associated with the affected Kaspersky products.