CVE-2007-1112
Last modified
CVE-2007-1112 is a vulnerability of currently unknown severity. Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.. EPSS estimates a 4.88% chance of exploitation in the next 30 days.
Description
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Kaspersky Lab | Kaspersky Anti-Virus | 6.0 | — |
| Kaspersky Lab | Kaspersky Internet Security | 6.0 | Maintenance Pack 2 |
References
- http://secunia.com/advisories/24778Patch, Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-014.htmlVendor Advisory
- http://secunia.com/advisories/24778Patch, Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-014.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1112?
How severe is CVE-2007-1112?
How do I fix CVE-2007-1112?
Are you affected by CVE-2007-1112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
