Title : avast! Home/Professional "aavmker4.sys" Privilege Escalation Issue VUPEN ID : VUPEN/ADV-2008-1034 CVE ID : CVE-2008-1625
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-03-31
Technical Description
A vulnerability has been identified in avast! Home/Professional, which could be exploited by local attackers to obtain elevated privileges. This issue is caused by an input validation error in the "aavmker4.sys" driver when processing user-supplied data, which could be exploited by unprivileged users to overwrite memory addresses via the IOCTL call 0xb2d60030 and execute arbitrary code with kernel privileges.