Security Advisory

CVE-2007-5043

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-09-24 00:00:00
Last updated 2024-08-07 15:17:27
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the NtCreateSection kernel SSDT hook or (2) cause a denial of service (avp.exe service outage) via the NtLoadDriver kernel SSDT hook. NOTE: this issue may partially overlap CVE-2006-3074.