vendor:
Kaspersky Antivirus
by:
Unknown
9
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: Kaspersky Antivirus
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:kaspersky:antivirus
Platforms Tested: All systems using Kaspersky Antivirus
Unknown
Remote Code Execution Vulnerability in Kaspersky Antivirus
The attached testcase triggers an access violation in Kaspersky Antivirus, leading to remote code execution as NT AUTHORITYSYSTEM. The vulnerability occurs when handling packed PE files, possibly packed using 'Yoda's protector'.
Mitigation:
Apply the latest security updates and patches provided by Kaspersky to fix this vulnerability.