CVE-2010-5075
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.9%
from disclosure to weapon0 days
Published on NVDDec 28
1st PoCAug 3
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/14533unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://web.archive.org/web/20120228033302/http://www.x90c.org/advisories/avast_internet_security_5.0_memory_corruption_advisory.txthttp://www.securityfocus.com/bid/42148http://x90c.blogspot.com/2011/11/avast-internet-security-aswfwsys-ioctl.htmlhttp://x90c.blogspot.com/2011/12/bid-42148-my-avast-kernel-driver-0day_01.html