First published: Wed Jan 28 2009(Updated: )
The GDTdiIcpt.sys driver in G DATA AntiVirus 2008, InternetSecurity 2008, and TotalCare 2008 populates kernel registers with IOCTL 0x8317001c input values, which allows local users to cause a denial of service (system crash) or gain privileges via a crafted IOCTL request, as demonstrated by execution of the KeSetEvent function with modified register contents.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
G Data AntiVirus 2008 | ||
G Data InternetSecurity 2008 | ||
G Data TotalCare 2008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6000 is classified as a high severity vulnerability due to its potential to cause system crashes and allow privilege escalation.
To mitigate CVE-2008-6000, users should update to the latest version of G DATA AntiVirus, InternetSecurity, or TotalCare that addresses this vulnerability.
CVE-2008-6000 affects G DATA AntiVirus 2008, InternetSecurity 2008, and TotalCare 2008 software.
CVE-2008-6000 enables local users to perform denial of service attacks or escalate privileges through crafted IOCTL requests.
CVE-2008-6000 can be exploited by local users with access to the vulnerable software.