First published: Mon May 24 2010(Updated: )
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kingsoft Webshield | <=3.5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2031 is classified as a high severity vulnerability that allows local users to overwrite kernel memory.
To fix CVE-2010-2031, update to Kingsoft Webshield version 3.5.1.3 or later.
CVE-2010-2031 can potentially allow local users to gain elevated privileges and execute arbitrary code.
Local users of Kingsoft Webshield versions 3.5.1.2 and earlier are affected by CVE-2010-2031.
Yes, there are known exploits that demonstrate the vulnerability of CVE-2010-2031.