Lucene search

K
cveMitreCVE-2007-1112
HistoryApr 06, 2007 - 12:19 a.m.

CVE-2007-1112

2007-04-0600:19:00
mitre
web.nvd.nist.gov
35
cve-2007-1112
kaspersky
anti-virus
internet security
activex controls
remote attackers
file manipulation

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.057

Percentile

93.4%

Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to “download” or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.

Affected configurations

Nvd
Node
kaspersky_labkaspersky_anti-virusMatch6.0windows_workstation
OR
kaspersky_labkaspersky_internet_securityMatch6.0maintenance_pack_2
VendorProductVersionCPE
kaspersky_labkaspersky_anti-virus6.0cpe:2.3:a:kaspersky_lab:kaspersky_anti-virus:6.0:*:windows_workstation:*:*:*:*:*
kaspersky_labkaspersky_internet_security6.0cpe:2.3:a:kaspersky_lab:kaspersky_internet_security:6.0:maintenance_pack_2:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.057

Percentile

93.4%