First published: Thu Oct 01 2009(Updated: )
Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast Pro Antivirus | =4.8.1351 | |
Avast Antivirus | =4.8.1351 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3522 is classified as a high-severity vulnerability due to its potential to cause system crashes and privilege escalation.
To address CVE-2009-3522, it is recommended to update avast! Home and Professional to version 4.8.1356 or later.
CVE-2009-3522 affects local users of avast! Home and Professional versions 4.8.1351 and potentially earlier releases.
CVE-2009-3522 can be exploited through a specially crafted IOCTL request that triggers a stack-based buffer overflow.
CVE-2009-3522 does not facilitate remote attacks as it requires local user access to the affected system.