[] NeoSense

Kaspersky (Multiple Products) - 'klim5.sys' Local Privilege Escalation

Author: Ruben Santamarta
type: local
platform: windows
port: 
date_added: 2009-02-02 
date_updated: 2014-04-11 
verified: 1 
codes: CVE-2009-0449;OSVDB-51726 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/33561/info

Multiple Kaspersky products are prone to a local privilege-escalation vulnerability because the applications fail to perform adequate boundary checks on user-supplied data.

A local attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.

This issue affects versions in the following product groups:

Kaspersky AV 2008
Kaspersky AV for WorkStations 6.0

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/32771.zip