CVE-2007-5043: Input Validation
Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the NtCreateSection kernel SSDT hook or (2) cause a denial of service (avp.exe service outage) via the NtLoadDriver kernel SSDT hook. NOTE: this issue may partially overlap CVE-2006-3074.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5043?
CVE-2007-5043 is classified as having a high severity due to its potential to cause denial of service and privilege escalation.
How do I fix CVE-2007-5043?
To mitigate CVE-2007-5043, it is recommended to upgrade to the latest version of Kaspersky Internet Security that addresses this vulnerability.
Can CVE-2007-5043 lead to system crashes?
Yes, CVE-2007-5043 can cause system crashes due to improper validation of parameters in the SSDT function handlers.
Who is affected by CVE-2007-5043?
CVE-2007-5043 affects users of Kaspersky Internet Security version 7.0.0.125.
What type of vulnerability is CVE-2007-5043?
CVE-2007-5043 is a local privilege escalation vulnerability that can be exploited by local users.