Local Privilege Escalation in Kaspersky Anti-Virus and Internet Security Products
CVE-2009-4452

Currently unrated

Key Information:

Summary

The vulnerability exists due to weak permissions set on the BASES directory in Kaspersky Anti-Virus and Internet Security products. This misconfiguration allows local users to gain unauthorized SYSTEM privileges by replacing executable files or DLLs with malicious software. Attackers can exploit these weak permissions to install Trojan horses or execute arbitrary code, jeopardizing the security of the affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.