Kaspersky Multiple Products 'Bases' Directory Insecure Permissions

high Nessus Plugin ID 43814

Synopsis

An antivirus product installed on the remote Windows host has a local privilege escalation vulnerability.

Description

The version of either Kaspersky Anti-Virus or Kaspersky Internet Security installed on the remote host has a local privilege escalation vulnerability.

The Everyone group has Full Control rights to the 'Bases' directory.
This directory contains antivirus bases, configuration files, and executable modules used by multiple Kaspersky products.

A local attacker could exploit this to execute arbitrary code with SYSTEM privileges.

Solution

Upgrade to one of the following versions :

- Kaspersky Anti-Virus 2010 (9.0.0.736)
- Kaspersky Internet Security 2010 (9.0.0.736)
- Kaspersky Anti-Virus 6.0 for Windows Workstations (6.0.4.1212)
- Kaspersky Anti-Virus 6.0 for Windows File Servers (6.0.4.1212)

See Also

https://seclists.org/bugtraq/2009/Dec/236

Plugin Details

Severity: High

ID: 43814

File Name: kaspersky_bases_perms_priv_escalation.nbin

Version: 1.228

Type: local

Agent: windows

Family: Windows

Published: 1/6/2010

Updated: 4/23/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: SMB/name, SMB/login, SMB/password, SMB/transport

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/21/2009

Vulnerability Publication Date: 12/16/2009

Reference Information

CVE: CVE-2009-4452

BID: 37354

CWE: 264

Secunia: 37398, 37730