CVE-2009-1824 describes a local privilege escalation vulnerability in the ps_drv.sys kernel driver found in several ArcaBit ArcaVir 2009 antivirus and security products. An attacker can exploit this by sending crafted METHOD_NEITHER IOCTL requests to the driver, allowing them to execute arbitrary kernel addresses and gain elevated privileges. With a CVSS score of 7.2, this vulnerability is considered highly severe, enabling a local attacker to achieve complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, though there is minimal community discussion or media coverage surrounding this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.4.3201.9CPE matchmatch criteria | cpe:2.3:a:arcabit:arcavir_2009_antivirus_protection:*:*:*:*:*:*:*:* | ||
<= 9.4.3204.9CPE matchmatch criteria | cpe:2.3:a:arcabit:arcavir_2009_home_protection:*:*:*:*:*:*:*:* | ||
<= 9.4.3202.9CPE matchmatch criteria | cpe:2.3:a:arcabit:arcavir_2009_internet_security:*:*:*:*:*:*:*:* | ||
<= 9.4.3203.9CPE matchmatch criteria | cpe:2.3:a:arcabit:arcavir_2009_system_protection:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.