CVE-2010-0705

avast! 4.8-5.0.418.0 - Local Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0705. PoCs published by ryujin.

AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in avast! 4.7's aavmker4.sys driver by leveraging arbitrary memory writes and function pointer manipulation to execute a ring0 payload, ultimately spawning a bindshell on port 4444.

Description

Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ryujin · pythonlocalwindows
https://www.exploit-db.com/exploits/12406

This exploit targets a privilege escalation vulnerability in avast! 4.7's aavmker4.sys driver by leveraging arbitrary memory writes and function pointer manipulation to execute a ring0 payload, ultimately spawning a bindshell on port 4444.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: avast! 4.7 (aavmker4.sys)
No auth needed
Prerequisites: avast! 4.7 installed on Windows XP SP2/SP3 · Local access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38363
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/62510
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38689
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0449
Vendor Advisory x_refsource_confirm
http://forum.avast.com/index.php?topic=55484.0
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509710/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023644
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38677
Various Sources x_refsource_misc
http://www.trapkit.de/advisories/TKADV2010-003.txt

Scores

EPSS 0.0093
EPSS Percentile 55.9%

Details

CWE
CWE-20
Status published
Products (25)
avast/avast_antivirus_home 4.8.1169
avast/avast_antivirus_home 4.8.1195
avast/avast_antivirus_home 4.8.1201
avast/avast_antivirus_home 4.8.1227
avast/avast_antivirus_home 4.8.1229
avast/avast_antivirus_home 4.8.1282
avast/avast_antivirus_home 4.8.1290
avast/avast_antivirus_home 4.8.1296
avast/avast_antivirus_home 4.8.1335
avast/avast_antivirus_home 4.8.1351
... and 15 more
Published Feb 25, 2010
Tracked Since Feb 18, 2026