CVE-2009-2966

Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 - Denial of Service via HTTP URL with Excessive Dots

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2966. PoCs published by Prakhar Prasad.

AI-analyzed exploit summary This exploit targets a vulnerability in Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010, causing a denial-of-service (DoS) by triggering excessive CPU usage and memory corruption through a maliciously crafted URL with consecutive dots. The PoC is delivered via an HTML file, which can be embedded in web pages or emails.

Description

avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Prakhar Prasad · htmldoswindows
https://www.exploit-db.com/exploits/9537

This exploit targets a vulnerability in Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010, causing a denial-of-service (DoS) by triggering excessive CPU usage and memory corruption through a maliciously crafted URL with consecutive dots. The PoC is delivered via an HTML file, which can be embedded in web pages or emails.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Kaspersky Internet Security 2010 9.0.0.459, Kaspersky Anti-Virus 2010 9.0.0.463
No auth needed
Prerequisites: Victim must visit a malicious webpage or open a malicious HTML email
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36405
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/57173
Exploit third-party-advisory x_refsource_sreasonres
http://securityreason.com/achievement_securityalert/66
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36084
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022754
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022755
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52571

Scores

EPSS 0.0640
EPSS Percentile 92.8%

Details

CWE
CWE-399
Status published
Products (2)
kaspersky/kaspersky_anti-virus 9.0.0.463
kaspersky/kaspersky_internet_security 9.0.0.459
Published Aug 25, 2009
Tracked Since Feb 18, 2026