CVE-2016-4307: Kaspersky Internet Security

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violation in KL1 kernel driver resulting in local system denial of service. An attacker can run a program from user-mode to trigger this vulnerability.

Affected products

  • Kaspersky Internet Security: version 16.0.0 only

Published 2017-01-06. Last modified 2026-06-17.