CVE-2010-3396: Buffer Overflow
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argument to IOCTL 0x80030004. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3396?
CVE-2010-3396 has been assigned a high severity rating due to the potential for local users to execute arbitrary code.
How do I fix CVE-2010-3396?
To mitigate CVE-2010-3396, update Kingsoft Antivirus to a version later than 2010.04.26.648.
What causes CVE-2010-3396?
CVE-2010-3396 is caused by a buffer overflow in the kavfm.sys driver when handling long arguments for the IOCTL command 0x80030004.
Who is affected by CVE-2010-3396?
Local users of Kingsoft Antivirus versions 2010.04.26.648 and earlier are affected by CVE-2010-3396.
Can CVE-2010-3396 be exploited remotely?
CVE-2010-3396 cannot be exploited remotely as it requires local access to the system.