CVE-2009-1824
Last modified
CVE-2009-1824 is a vulnerability of currently unknown severity. The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet Security 9.4.3202.9 and earlier, ArcaVir 2009 System Protection 9.4.3203.9 and earlier, and ArcaBit 2009 Home Protection 9.4.3204.9 and earlier, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\ps_drv containing arbitrary kernel addresses, as demonstrated using the (1) 0x2A7B802B and possibly (2) 0x2A7B8004 and (3) 0x2A7B802F IOCTLs.. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet Security 9.4.3202.9 and earlier, ArcaVir 2009 System Protection 9.4.3203.9 and earlier, and ArcaBit 2009 Home Protection 9.4.3204.9 and earlier, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\ps_drv containing arbitrary kernel addresses, as demonstrated using the (1) 0x2A7B802B and possibly (2) 0x2A7B8004 and (3) 0x2A7B802F IOCTLs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arcabit | Arcavir 2009 Antivirus Protection | <= 9.4.3201.9 |
| Arcabit | Arcavir 2009 Home Protection | <= 9.4.3204.9 |
| Arcabit | Arcavir 2009 Internet Security | <= 9.4.3202.9 |
| Arcabit | Arcavir 2009 System Protection | <= 9.4.3203.9 |
References
- http://secunia.com/advisories/35260Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1428Vendor Advisory
- http://secunia.com/advisories/35260Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1428Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1824?
How severe is CVE-2009-1824?
How do I fix CVE-2009-1824?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1818SQL injection vulnerability in admin/admin_manager.asp in Ma…
- CVE-2009-1819SQL injection vulnerability in product.php in 2daybiz Custom…
- CVE-2009-1820Cross-site scripting (XSS) vulnerability in product.php in 2…
- CVE-2009-1821DMXReady Registration Manager 1.1 stores sensitive informati…
- CVE-2009-1822Multiple PHP remote file inclusion vulnerabilities in the In…
- CVE-2009-1823Cross-site scripting (XSS) vulnerability in the Print (aka P…
- CVE-2009-1825modules/admuser.php in myColex 1.4.2 does not require admini…
- CVE-2009-1826modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not re…
- CVE-2009-1827The SVG component in Mozilla Firefox 3.0.4 allows remote att…
- CVE-2009-1828Mozilla Firefox 3.0.10 allows remote attackers to cause a de…
- CVE-2009-1829Unspecified vulnerability in the PCNFSD dissector in Wiresha…
- CVE-2009-1830Stack-based buffer overflow in Soulseek 156 and 157 NS allow…
Are you affected by CVE-2009-1824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
