CVE-2008-1518
 
Severity Score
7.2
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack-based buffer overflow in kl1.sys in Kaspersky Anti-Virus 6.0 and 7.0 and Internet Security 6.0 and 7.0 allows local users to gain privileges via an IOCTL 0x800520e8 call.
Desbordamiento de búfer basado en pila en kl1.sys en Kaspersky Anti-Virus 6.0 y 7.0, y en Internet Security 6.0 y 7.0, permite a usuarios locales aumentar privilegios a través de una llamada IOCTL 0x800520e8
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-03-25 CVE Reserved
- 2008-06-05 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=704 | Third Party Advisory | |
http://securitytracker.com/id?1020195 | Vdb Entry | |
http://securitytracker.com/id?1020196 | Vdb Entry | |
http://www.kaspersky.com/technews?id=203038727 | X_refsource_confirm | |
http://www.vupen.com/english/advisories/2008/1739 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42849 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/30534 | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" | 6.0 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "6.0" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" | 7.0 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "7.0" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Internet Security Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" | 6.0 Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" and version "6.0" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Internet Security Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" | 7.0 Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" and version "7.0" | - |
Affected
|