CVE-2009-4114

Kaspersky Anti-Virus <9.0.0.736 - DoS

Title source: llm

Description

kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of service (system crash) via IOCTL requests using crafted kernel addresses that trigger memory corruption, possibly related to klavemu.kdl.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Heurs · cdoswindows
https://www.exploit-db.com/exploits/10164

Scores

EPSS 0.0065
EPSS Percentile 70.9%

Details

CWE
CWE-20
Status published
Products (1)
kaspersky/kaspersky_anti-virus 9.0.0.463
Published Nov 30, 2009
Tracked Since Feb 18, 2026