VYPR
Medium severity5.5NVD Advisory· Published Jan 6, 2017· Updated May 6, 2026

CVE-2016-4306

CVE-2016-4306

Description

Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability.

Affected products

2
  • Kaspersky/Total Securityv5
    Range: 16.0.0.614
  • cpe:2.3:a:kaspersky:total_security:16.0.0.614:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.