Lucene search

K
kasperskyKaspersky LabKLA10021
HistorySep 07, 2012 - 12:00 a.m.

KLA10021 LPE vulnerability in DAEMON Tools

2012-09-0700:00:00
Kaspersky Lab
threats.kaspersky.com
23

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

16.1%

An unspecified vulnerability was found in the DAEMON Tools. By exploiting this vulnerability malicious users can gain privileges. This vulnerability can be exploited from the network at a point related to path search. Via a Trojan horse.

Original advisories

NVD

Exploitation

Public exploits exist for this vulnerability.

Related products

DAEMON-Tools-Pro-Standard-Advanced

DAEMON-Tools-Lite

DAEMON-Tools-Pro

CVE list

CVE-2010-5239 high

Solution

Update to latest version

DAEMON Tools

Impacts

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • DAEMON Tools Lite version 4.35.6.0091DAEMON Tools Pro Standard 4.36.0309.0160

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

16.1%