CVE-2009-4452

Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
kaspersky_labkaspersky_anti-virus
5.0.712
kaspersky_labkaspersky_anti-virus
6.0.3.837
kaspersky_labkaspersky_anti-virus
6.0.3.837
kaspersky_labkaspersky_anti-virus
7.0.1.325
kaspersky_labkaspersky_anti-virus_2009
8.0.0.454
kaspersky_labkaspersky_anti-virus_2010
9.0.0.463
kaspersky_labkaspersky_anti-virus_personal
5.0
kaspersky_labkaspersky_anti-virus_personal
5.0.227
kaspersky_labkaspersky_anti-virus_personal
5.0.228
kaspersky_labkaspersky_anti-virus_personal
5.0.325
kaspersky_labkaspersky_internet_security
7.0.1.325
kaspersky_labkaspersky_internet_security_2009
8.0.0.506
kaspersky_labkaspersky_internet_security_2010
9.0.0.463
𝑥
= Vulnerable software versions
Common Weakness Enumeration