Local Code Execution Vulnerability in Kaspersky Labs Anti-Virus Products
CVE-2006-4926

Currently unrated

Summary

The NDIS-TDI Hooking Engine utilized by Kaspersky Labs Anti-Virus and possibly other security products contains a vulnerability that permits local users to execute arbitrary code. This flaw arises from the handling of crafted IRP structures containing invalid addresses during the execution of a specific IOCTL command (0x80052110), potentially leading to elevated privileges and unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.