CVE-2006-3074 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7.2% (pctl 94)
Patch early
A public exploit exists.
Description
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 7.18% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-06-19 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| kaspersky | kaspersky anti-virus |
| kaspersky | kaspersky internet security |
| microsoft | windows |
| microsoft | windows server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Kaspersky Internet Security 6.0 - SSDT Hooks Multiple Local Vulnerabilities | 2007-06-15 |
References
- http://secunia.com/advisories/20629
- http://secunia.com/advisories/25603
- http://uninformed.org/index.cgi?v=4&a=4&p=4
- http://uninformed.org/index.cgi?v=4&a=4&p=7
- http://www.kaspersky.com/technews?id=203038695
- http://www.matousec.com/info/advisories/Kaspersky-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php
- http://www.rootkit.com/board.php?did=edge726&closed=0&lastx=15
- http://www.rootkit.com/newsread.php?newsid=726
- http://www.securityfocus.com/archive/1/471453/100/0/threaded
- http://www.securityfocus.com/bid/18341
- http://www.securityfocus.com/bid/24491
- http://www.securitytracker.com/id?1018257
- http://www.vupen.com/english/advisories/2006/2333
- http://www.vupen.com/english/advisories/2007/2145
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27104
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34875
- http://secunia.com/advisories/20629
- http://secunia.com/advisories/25603
- http://uninformed.org/index.cgi?v=4&a=4&p=4
- http://uninformed.org/index.cgi?v=4&a=4&p=7
→ the Explorer · watch your stack · NVD