// For flags

CVE-2008-1625

Avast! 4.7 - 'aavmker4.sys' Local Privilege Escalation

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.

aavmker4.sys en avast! Home y Professional 4.7 para Windows, no valida de forma correcta la entrada a IOCTL 0xb2d60030, esto permite a usuarios locales obtener privilegios a través de cierta solicitud IOCTL.

Avast! version 4.7 aavmker4.sys local privilege escalation vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-04-02 CVE Reserved
  • 2008-04-02 CVE Published
  • 2010-04-27 First Exploit
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Avast
Search vendor "Avast"
Avast Antivirus Home
Search vendor "Avast" for product "Avast Antivirus Home"
4.7.827
Search vendor "Avast" for product "Avast Antivirus Home" and version "4.7.827"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Home
Search vendor "Avast" for product "Avast Antivirus Home"
4.7.844
Search vendor "Avast" for product "Avast Antivirus Home" and version "4.7.844"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Home
Search vendor "Avast" for product "Avast Antivirus Home"
4.7.869
Search vendor "Avast" for product "Avast Antivirus Home" and version "4.7.869"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Home
Search vendor "Avast" for product "Avast Antivirus Home"
4.7.1043
Search vendor "Avast" for product "Avast Antivirus Home" and version "4.7.1043"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Home
Search vendor "Avast" for product "Avast Antivirus Home"
4.7.1098
Search vendor "Avast" for product "Avast Antivirus Home" and version "4.7.1098"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Professional
Search vendor "Avast" for product "Avast Antivirus Professional"
4.7.827
Search vendor "Avast" for product "Avast Antivirus Professional" and version "4.7.827"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Professional
Search vendor "Avast" for product "Avast Antivirus Professional"
4.7.844
Search vendor "Avast" for product "Avast Antivirus Professional" and version "4.7.844"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Professional
Search vendor "Avast" for product "Avast Antivirus Professional"
4.7.1043
Search vendor "Avast" for product "Avast Antivirus Professional" and version "4.7.1043"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Professional
Search vendor "Avast" for product "Avast Antivirus Professional"
4.7.1098
Search vendor "Avast" for product "Avast Antivirus Professional" and version "4.7.1098"
windows
Affected