CVE-2009-4049
avast! Home and Professional 4.8.1356.0 - Memory Corruption
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-4049. PoCs published by Evilcry, fengjixuchui.
AI-analyzed exploit summary This exploit targets a kernel pool corruption vulnerability in Avast! Antivirus 4.8.1356 via the aswRdr.sys driver. It uses DeviceIoControl to trigger the vulnerability, potentially leading to local privilege escalation or denial-of-service.
Description
Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted arguments to IOCTL 0x80002024.
Exploits (2)
This exploit targets a kernel pool corruption vulnerability in Avast! Antivirus 4.8.1356 via the aswRdr.sys driver. It uses DeviceIoControl to trigger the vulnerability, potentially leading to local privilege escalation or denial-of-service.
This repository contains a functional exploit for CVE-2009-4049, a heap-based buffer overflow in avast! TDI RDR driver (aswRdr.sys) version 4.8.1356.0. The exploit demonstrates memory corruption via a crafted IOCTL call, though it notes limitations in achieving full control over memory contents.