Vulnerability Report

CVE-2006-3074

Title: Kaspersky Kaspersky Anti-Virus Memory Corruption

Memory Corruption

Proof Of Concept

PoC Available for CVE-2006-3074

CWE Category CWE-119
Published Date Jun 19, 2006
Modified Date Jun 16, 2026
Exploit Status Available
Score 5.0 CVSS v2.0
Exploit Probability (EPSS)
7.18%

Vulnerability Summary

CVE-2006-3074: klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.

Impacted Vendors

Reference Links

http://secunia.com/advisories/20629 http://secunia.com/advisories/25603 http://uninformed.org/index.cgi?v=4&a=4&p=4 http://uninformed.org/index.cgi?v=4&a=4&p=7 http://www.kaspersky.com/technews?id=203038695 http://www.matousec.com/info/advisories/Kaspersky-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php http://www.rootkit.com/board.php?did=edge726&closed=0&lastx=15 http://www.rootkit.com/newsread.php?newsid=726 http://www.securityfocus.com/archive/1/471453/100/0/threaded http://www.securityfocus.com/bid/18341 http://www.securityfocus.com/bid/24491 http://www.securitytracker.com/id?1018257 http://www.vupen.com/english/advisories/2006/2333 http://www.vupen.com/english/advisories/2007/2145 https://exchange.xforce.ibmcloud.com/vulnerabilities/27104 https://exchange.xforce.ibmcloud.com/vulnerabilities/34875 http://secunia.com/advisories/20629 http://secunia.com/advisories/25603 http://uninformed.org/index.cgi?v=4&a=4&p=4 http://uninformed.org/index.cgi?v=4&a=4&p=7 http://www.kaspersky.com/technews?id=203038695 http://www.matousec.com/info/advisories/Kaspersky-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php http://www.rootkit.com/board.php?did=edge726&closed=0&lastx=15 http://www.rootkit.com/newsread.php?newsid=726 http://www.securityfocus.com/archive/1/471453/100/0/threaded http://www.securityfocus.com/bid/18341 http://www.securityfocus.com/bid/24491 http://www.securitytracker.com/id?1018257 http://www.vupen.com/english/advisories/2006/2333 http://www.vupen.com/english/advisories/2007/2145 https://exchange.xforce.ibmcloud.com/vulnerabilities/27104 https://exchange.xforce.ibmcloud.com/vulnerabilities/34875
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:N/I:N/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2006-3074 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/30192
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected Stack

No specific products linked.