CVE Vulnerabilities

CVE-2007-1112

Published: Apr 06, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to download or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.

Affected Software

NameVendorStart VersionEnd Version
Kaspersky_anti-virusKaspersky_lab6.0 (including)6.0 (including)
Kaspersky_internet_securityKaspersky_lab6.0-maintenance_pack_2 (including)6.0-maintenance_pack_2 (including)

References