Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-4452


Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse.


Published

2009-12-29T20:41:20.577

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.1

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application kaspersky_lab kaspersky_anti-virus 5.0.712 Yes
Application kaspersky_lab kaspersky_anti-virus 6.0.3.837 Yes
Application kaspersky_lab kaspersky_anti-virus 6.0.3.837 Yes
Application kaspersky_lab kaspersky_anti-virus 7.0.1.325 Yes
Application kaspersky_lab kaspersky_anti-virus_2009 8.0.0.454 Yes
Application kaspersky_lab kaspersky_anti-virus_2010 9.0.0.463 Yes
Application kaspersky_lab kaspersky_anti-virus_personal 5.0 Yes
Application kaspersky_lab kaspersky_anti-virus_personal 5.0.227 Yes
Application kaspersky_lab kaspersky_anti-virus_personal 5.0.228 Yes
Application kaspersky_lab kaspersky_anti-virus_personal 5.0.325 Yes
Application kaspersky_lab kaspersky_internet_security 7.0.1.325 Yes
Application kaspersky_lab kaspersky_internet_security_2009 8.0.0.506 Yes
Application kaspersky_lab kaspersky_internet_security_2010 9.0.0.463 Yes

References