Kaspersky Antivirus DEX File Format Parsing Memory Corruption

Discussion in 'News Aggregator' started by Packet Storm, 14 Oct 2015.

  1. Packet Storm

    Packet Storm Guest

    Fuzzing the DEX file format found a crash that loads a function pointer from an attacker controlled pointer, on Windows this results in a call to an unmapped address. This is obviously exploitable for remote, zero-interaction code execution as NT AUTHORITY\SYSTEM on any system with Kaspersky Antivirus.

    Continue reading...
     

Share This Page

Loading...