CVE-2007-1879: Critical severity Kaspersky Lab Kaspersky Anti-virus vulnerability
The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anonymous FTP session that invokes the PUT command. NOTE: this issue might be related to CVE-2007-1112.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1879?
CVE-2007-1879 is considered to have a high severity due to its ability to allow remote attackers to read arbitrary files.
How do I fix CVE-2007-1879?
To fix CVE-2007-1879, update Kaspersky Anti-Virus or Kaspersky Internet Security to at least Maintenance Pack 2 build 6.0.2.614.
What are the affected versions for CVE-2007-1879?
CVE-2007-1879 affects Kaspersky Anti-Virus 6.0 and Kaspersky Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614.
What type of attack does CVE-2007-1879 describe?
CVE-2007-1879 describes a remote file access vulnerability that is exploited via an outbound anonymous FTP session.
Are there any known exploits for CVE-2007-1879?
Yes, there are known exploits for CVE-2007-1879 that leverage the StartUploading function to read arbitrary files.