CVE-2009-3523

Avast Antivirus Home < 4.8.1351 - Improper Input Validation

Title source: rule

Description

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

Exploits (1)

exploitdb WORKING POC
pythonlocalwindows
https://www.exploit-db.com/exploits/12406

Scores

EPSS 0.0016
EPSS Percentile 36.4%

Details

CWE
CWE-20
Status published
Products (29)
avast/avast_antivirus_home 4.7.827
avast/avast_antivirus_home 4.7.844
avast/avast_antivirus_home 4.7.869
avast/avast_antivirus_home 4.7.1043
avast/avast_antivirus_home 4.7.1098
avast/avast_antivirus_home 4.8.1169
avast/avast_antivirus_home 4.8.1195
avast/avast_antivirus_home 4.8.1201
avast/avast_antivirus_home 4.8.1227
avast/avast_antivirus_home 4.8.1229
... and 19 more
Published Oct 01, 2009
Tracked Since Feb 18, 2026