CVE-2009-3523

Avast Antivirus Home < 4.8.1351 - Improper Input Validation

Title source: rule

Description

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

Exploits (1)

exploitdb WORKING POC
pythonlocalwindows
https://www.exploit-db.com/exploits/12406

Scores

EPSS 0.0016
EPSS Percentile 36.5%

Classification

CWE
CWE-20
Status draft

Affected Products (29)

avast/avast_antivirus_home < 4.8.1351
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
avast/avast_antivirus_home
... and 14 more

Timeline

Published Oct 01, 2009
Tracked Since Feb 18, 2026