CVE-2009-4452
Kaspersky Lab (Multiple Products) - Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse.
Kaspersky Anti-Virus v5.0 (v5.0.712); Antivirus Personal v5.0.x; Anti-Virus v6.0 (v6.0.3.837), v7 (v7.0.1.325), 2009 (v8.0.0.x), and 2010 (v9.0.0.463); y Internet Security v7 (v7.0.1.325), 2009 (v8.0.0.x), and 2010 (v9.0.0.463); usan permisos débiles (Todo el mundo: Control Total) en el directorio BASES, lo que permite a usuarios locales obtener privilegios de SYSTEM sustituyendo un ejecutable o DLL con un caballo de troya.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-12-16 First Exploit
- 2009-12-29 CVE Reserved
- 2009-12-29 CVE Published
- 2023-08-22 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/508508/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1023366 | Vdb Entry | |
http://www.securitytracker.com/id?1023367 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/10484 | 2009-12-16 | |
http://www.exploit-db.com/exploits/10484 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/37398 | 2018-10-10 | |
http://secunia.com/advisories/37730 | 2018-10-10 | |
http://www.vupen.com/english/advisories/2009/3573 | 2018-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" | 5.0.712 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "5.0.712" | windows_workstations |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" | 6.0.3.837 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "6.0.3.837" | windows_file_servers |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" | 6.0.3.837 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "6.0.3.837" | windows_workstation |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" | 7.0.1.325 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus" and version "7.0.1.325" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus 2009 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus 2009" | 8.0.0.454 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus 2009" and version "8.0.0.454" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus 2010 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus 2010" | 9.0.0.463 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus 2010" and version "9.0.0.463" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Personal Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" | 5.0 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" and version "5.0" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Personal Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" | 5.0.227 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" and version "5.0.227" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Personal Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" | 5.0.228 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" and version "5.0.228" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Anti-virus Personal Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" | 5.0.325 Search vendor "Kaspersky Lab" for product "Kaspersky Anti-virus Personal" and version "5.0.325" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Internet Security Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" | 7.0.1.325 Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security" and version "7.0.1.325" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Internet Security 2009 Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security 2009" | 8.0.0.506 Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security 2009" and version "8.0.0.506" | - |
Affected
| ||||||
Kaspersky Lab Search vendor "Kaspersky Lab" | Kaspersky Internet Security 2010 Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security 2010" | 9.0.0.463 Search vendor "Kaspersky Lab" for product "Kaspersky Internet Security 2010" and version "9.0.0.463" | - |
Affected
|