[2/5] avast! Home/Professional aavmker4.sys Privilege Escalation
:Tobias Klein has reported a vulnerability in avast! Home/Professional, which can be exploited by malicious, local users to gain escalated privileges.An input validation error within the 0xb2d60030 IOCTL handler of the aavmker4.sys driver can be exploited e.g. to overwrite arbitrary kernel memory via a specially crafted IOCTL request.The vulnerability is reported in version 4.7. Other versions may also be affected.Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.Solution:Update to version 4.8.1169.http://www.avast.com/eng/download.htmlProvided and/or discovered by:Tobias KleinOriginal Advisory:avast!:http://www.avast.com/eng/avast-4-home_pro-revision-history.htmlTobias Klein:http://www.trapkit.de/advisories/TKADV2008-002.txt
Original post by amit
Posted in Advisories - Exploits |
| [2/5] avast! Home/Professional aavmker4.sys Privilege Escalation