CVE-2006-3074
Last modified
CVE-2006-3074 is a vulnerability of currently unknown severity. klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.. EPSS estimates a 7.05% chance of exploitation in the next 30 days.
Description
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kaspersky | Kaspersky Anti-Virus | 6.0 |
| Kaspersky | Kaspersky Anti-Virus | 7.0 |
| Kaspersky | Kaspersky Internet Security | 6.0 |
| Kaspersky | Kaspersky Internet Security | 7.0 |
References
- http://secunia.com/advisories/20629Vendor Advisory
- http://secunia.com/advisories/25603Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2333Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2145Vendor Advisory
- http://secunia.com/advisories/20629Vendor Advisory
- http://secunia.com/advisories/25603Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2333Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2145Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3074?
How severe is CVE-2006-3074?
How do I fix CVE-2006-3074?
Are you affected by CVE-2006-3074?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
