First published: Fri Jan 06 2017(Updated: )
A denial of service vulnerability exists in the syscall filtering functionality of the Kaspersky Internet Security KLIF driver. A specially crafted native api call request can cause a access violation exception in KLIF kernel driver resulting in local denial of service. An attacker can run program from user-mode to trigger this vulnerability.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Internet Security 2010 | =16.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4304 is classified as a denial of service vulnerability.
To mitigate CVE-2016-4304, update Kaspersky Internet Security to the latest version provided by the vendor.
CVE-2016-4304 specifically affects Kaspersky Internet Security version 16.0.0.
CVE-2016-4304 requires local access to exploit, making it a local denial of service vulnerability.
Exploitation of CVE-2016-4304 can lead to access violation exceptions, resulting in a local denial of service.