Cybertrion Systems

[2/5] avast! Home/Professional aavmker4.sys Privilege Escalation

March 31st, 2008 by
[2/5] avast! Home/Professional aavmker4.sys Privilege Escalation

:Tobias Klein has reported a vulnerability in avast! Home/Professional, which can be exploited by malicious, local users to gain escalated privileges.An input validation error within the 0xb2d60030 IOCTL handler of the aavmker4.sys driver can be exploited e.g. to overwrite arbitrary kernel memory via a specially crafted IOCTL request.The vulnerability is reported in version 4.7. Other versions may also be affected.Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.Solution:Update to version 4.8.1169.http://www.avast.com/eng/download.htmlProvided and/or discovered by:Tobias KleinOriginal Advisory:avast!:http://www.avast.com/eng/avast-4-home_pro-revision-history.htmlTobias Klein:http://www.trapkit.de/advisories/TKADV2008-002.txt

Original post by amit

[2/5] avast! Home/Professional aavmker4.sys Privilege Escalation

Related Articles:
  • [3/5] avast! Home/Professional Unspecified TAR File Processing Vulnerability
  • [4/5] avast! Home/Professional TAR File Processing Heap Corruption
  • [2/5] avast! Zoo Denial of Service Vulnerability
  • [2/5] Sun Solaris PostgreSQL SECURITY DEFINER Privilege Escalation
  • [2/5] IBM AIX “at” Command Privilege Escalation Vulnerability


  • Posted in Advisories - Exploits | | [2/5] avast! Home/Professional aavmker4.sys Privilege Escalation

    << [4/5] Slackware update for xine-lib | [3/5] GnuPG Duplicated IDs Memory Corruption >>