KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error in the KAVSafe.sys driver occurs, allowing a local attacker to corrupt kernel memory and allow the attacker to gain system privileges in order to execute arbitrary code via a specially crafted 830020D4h IOCTL.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Uncoordinated Disclosure
Solution
Upgrade to the latest version, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.