// For flags

CVE-2008-1518

 

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in kl1.sys in Kaspersky Anti-Virus 6.0 and 7.0 and Internet Security 6.0 and 7.0 allows local users to gain privileges via an IOCTL 0x800520e8 call.

Desbordamiento de búfer basado en pila en kl1.sys en Kaspersky Anti-Virus 6.0 y 7.0, y en Internet Security 6.0 y 7.0, permite a usuarios locales aumentar privilegios a través de una llamada IOCTL 0x800520e8

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-03-25 CVE Reserved
  • 2008-06-05 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Kaspersky Lab
Search vendor "Kaspersky Lab"
Kaspersky Anti-virus
Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus"
6.0
Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "6.0"
-
Affected
Kaspersky Lab
Search vendor "Kaspersky Lab"
Kaspersky Anti-virus
Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus"
7.0
Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "7.0"
-
Affected
Kaspersky Lab
Search vendor "Kaspersky Lab"
Kaspersky Internet Security
Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security"
6.0
Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" and version "6.0"
-
Affected
Kaspersky Lab
Search vendor "Kaspersky Lab"
Kaspersky Internet Security
Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security"
7.0
Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" and version "7.0"
-
Affected