CVE-2009-3523

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
avastavast_antivirus_home
𝑥
≤ 4.8.1351
avastavast_antivirus_home
4.7.827
avastavast_antivirus_home
4.7.844
avastavast_antivirus_home
4.7.869
avastavast_antivirus_home
4.7.1043
avastavast_antivirus_home
4.7.1098
avastavast_antivirus_home
4.8.1169
avastavast_antivirus_home
4.8.1195
avastavast_antivirus_home
4.8.1201
avastavast_antivirus_home
4.8.1227
avastavast_antivirus_home
4.8.1229
avastavast_antivirus_home
4.8.1282
avastavast_antivirus_home
4.8.1290
avastavast_antivirus_home
4.8.1296
avastavast_antivirus_home
4.8.1335
avastavast_antivirus_professional
𝑥
≤ 4.8.1351
avastavast_antivirus_professional
4.7.827
avastavast_antivirus_professional
4.7.844
avastavast_antivirus_professional
4.7.1043
avastavast_antivirus_professional
4.7.1098
avastavast_antivirus_professional
4.8.1169
avastavast_antivirus_professional
4.8.1195
avastavast_antivirus_professional
4.8.1201
avastavast_antivirus_professional
4.8.1227
avastavast_antivirus_professional
4.8.1229
avastavast_antivirus_professional
4.8.1282
avastavast_antivirus_professional
4.8.1290
avastavast_antivirus_professional
4.8.1296
avastavast_antivirus_professional
4.8.1335
𝑥
= Vulnerable software versions