JVN#31517714
Kingsoft Internet Security 2011 vulnerable to denial-of-service
Overview
Kingsoft Internet Security 2011 contains a denial-of-service (DoS) vulnerability.
Products Affected
- Kingsoft Internet Security 2011
Note that Kingsoft Internet Security 2012 is not affected by this vulnerability.
Description
Kingsoft Internet Security 2011 contains a vulnerability in the device driver, which may result in a denial-of-service (DoS).
Impact
An attacker that can login to the system with the software running may cause a denial-of-service (DoS).
Solution
Update the Software
Update to the latest version according to the information provided by the developer.
According to the developer, the automatic update which addresses this vulnerability has been provided since February 20, 2012.
Vendor Status
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2012.03.01
Measures | Conditions | Severity |
---|---|---|
Access Required | requires you to login into the box to a shell or remote desktop |
|
Authentication | login caused to be created by an administrator |
|
User Interaction Required | the vulnerability can be exploited without an honest user taking any action |
|
Exploit Complexity | some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls) |
|
Credit
Satoshi TANDA of Fourteenforty Research Institute Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2012-0321 |
JVN iPedia |
JVNDB-2012-000019 |