CVE-2009-3523: Input Validation
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3523?
CVE-2009-3523 is classified as a high severity vulnerability due to its ability to allow local users to gain elevated privileges.
How do I fix CVE-2009-3523?
To mitigate CVE-2009-3523, update to the latest version of Avast Antivirus that is patched against this vulnerability.
What versions are affected by CVE-2009-3523?
CVE-2009-3523 affects multiple versions of Avast Antivirus, specifically versions prior to 4.8.1356.
Can CVE-2009-3523 be exploited remotely?
No, CVE-2009-3523 can only be exploited locally by authenticated users.
What type of vulnerability is CVE-2009-3523?
CVE-2009-3523 is a privilege escalation vulnerability that results from improper input validation in the driver.