First published: Mon Nov 30 2009(Updated: )
kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of service (system crash) via IOCTL requests using crafted kernel addresses that trigger memory corruption, possibly related to klavemu.kdl.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | =9.0.0.463 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4114 has a moderate severity rating due to its potential to cause a denial of service through memory corruption.
To fix CVE-2009-4114, update Kaspersky Anti-Virus to version 9.0.0.736 or later.
CVE-2009-4114 affects Kaspersky Anti-Virus 2010 version 9.0.0.463 and potentially earlier versions.
CVE-2009-4114 is a memory corruption vulnerability that can lead to a system crash.
CVE-2009-4114 is only exploitable by local users due to its nature of requiring crafted IOCTL requests.