Flaw found in Kaspersky antivirus

A 'critical' flaw in Kaspersky Lab's antivirus software could let an attacker commandeer systems that use the products, a security researcher warned on Monday.

The problem lies in Kaspersky's antivirus library, security researcher Alex Wheeler wrote in an advisory. The vulnerability likely affects multiple Kaspersky products on various platforms because the library is used throughout the company's consumer and corporate software, he said.

Additionally, third-party products that use Kaspersky's antivirus technology could also be vulnerable, Wheeler said.

A remote attacker could exploit the heap overflow flaw by sending a malformed CAB file -- a compression file -- to a vulnerable system, the French Security Incident Response Team said in an advisory. The CAB file could be sent in an e-mail, for example, and once the Kaspersky antivirus scanner had accepted it, the malicious code would be in the system. No user interaction is required, Wheeler said. FrSirt describes the issue as "critical," its highest rating.

News source: ZDNet Australia

Report a problem with article
Previous Story

PvP and updated website for GTA : LCS

Next Story

Coming To A PC Near You - Google Office?

1 Comments

Commenting is disabled on this article.

if the cab file is sent in the mail, the anti-virus will scan it when your mail client checks the mail


Major flaw there