// For flags

CVE-2009-3522

Avast! 4.8.1351.0 AntiVirus - 'aswMon2.sys' Kernel Memory Corruption

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.

Desbordamiento de búfer basado en pila en aswMon2.sys en avast! Home y Professional para Windows v4.8.1351, y probablemente otras versiones anteriores v4.8.1356, permite a usuarios locales causar una denegación de servicios (caída sistema) y probablemente obtener privilegios a través de peticiones IOCTL manipuladas en IOCTL 0xb2c80018.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-10-01 CVE Reserved
  • 2009-10-01 CVE Published
  • 2009-11-17 First Exploit
  • 2023-05-25 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Avast
Search vendor "Avast"
Avast Antivirus Home
Search vendor "Avast" for product "Avast Antivirus Home"
4.8.1351
Search vendor "Avast" for product "Avast Antivirus Home" and version "4.8.1351"
windows
Affected
Avast
Search vendor "Avast"
Avast Antivirus Professional
Search vendor "Avast" for product "Avast Antivirus Professional"
4.8.1351
Search vendor "Avast" for product "Avast Antivirus Professional" and version "4.8.1351"
windows
Affected