Lucene search

K
cveMitreCVE-2009-3522
HistoryOct 01, 2009 - 5:00 p.m.

CVE-2009-3522

2009-10-0117:00:00
CWE-119
mitre
web.nvd.nist.gov
29
cve-2009-3522
buffer overflow
avast
windows
ioctl
denial of service
privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

High

EPSS

0

Percentile

10.3%

Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.

Affected configurations

Nvd
Node
avastavast_antivirus_homeMatch4.8.1351windows
OR
avastavast_antivirus_professionalMatch4.8.1351windows
VendorProductVersionCPE
avastavast_antivirus_home4.8.1351cpe:2.3:a:avast:avast_antivirus_home:4.8.1351:*:windows:*:*:*:*:*
avastavast_antivirus_professional4.8.1351cpe:2.3:a:avast:avast_antivirus_professional:4.8.1351:*:windows:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

High

EPSS

0

Percentile

10.3%