CVE-2016-4305: Medium severity kaspersky internet security suite vulnerability
Published Jan 6, 2017
·Updated
A denial of service vulnerability exists in the syscall filtering functionality of Kaspersky Internet Security KLIF driver. A specially crafted native api call can cause a access violation in KLIF kernel driver resulting in local denial of service. An attacker can run program from user-mode to trigger this vulnerability.
Affected Software
1 affected component
Kaspersky Internet Security=16.0.0
Event History
Jan 6, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-4305?
CVE-2016-4305 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-4305?
The recommended fix for CVE-2016-4305 is to update Kaspersky Internet Security to the latest version.
3
What software is affected by CVE-2016-4305?
CVE-2016-4305 affects Kaspersky Internet Security version 16.0.0.
4
Can CVE-2016-4305 be exploited remotely?
CVE-2016-4305 requires local access for exploitation, so it cannot be exploited remotely.
5
What are the consequences of CVE-2016-4305?
Exploitation of CVE-2016-4305 can lead to a local denial of service condition.