Dec
22
2011
Vulnerability-Lab Team discovered a Memory & Pointer Corruption Vulnerability on Kaspersky Internet Security 2011/2012 & Kaspersky Anti-Virus 2011/2012.
Details:
The vulnerability is caused by an invalid pointer corruption when processing a corrupt .cfg file through the kaspersky exception filters, which could be exploited by attackers to crash the complete software process.
The bug is located over the basegui.ppl & basegui.dll when processing a .cfg file import.
Vulnerable Modules:
[+] CFG IMPORT
Affected Version(s):
– Kaspersky Anti-Virus 2012 & Kaspersky Internet Security 2012
– KIS 2012 v12.0.0.374
– KAV 2012 v12.x
– Kaspersky Anti-Virus 2011 & Kaspersky Internet Security 2011
– KIS 2011 v11.0.0.232 (a.b)
– KAV 11.0.0.400
– KIS 2011 v12.0.0.374
– Kaspersky Anti-Virus 2010 & Kaspersky Internet Security 2010
Severity:
Medium
Credits:
Vulnerability Research Laboratory – Benjamin K.M. (Rem0ve)
Original Advisory:
– http://www.vulnerability-lab.com/get_content.php?id=129
– http://www.vulnerability-lab.com/get_content.php?id=19
Tags: Bugs, Kaspersky, Kaspersky Antivirus, Kaspersky Vulnerability, Memory Corruption, Memory Corruption Vulnerability, News, Vulnerabilities, Vulnerability
Filed in Exploits, Stories/News, Vulnerabilities | Prasanna Sherekar | Comments Off
Dec
21
2011
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user’s system.
The vulnerability is caused due to an error in win32k.sys and can be exploited to corrupt memory via e.g. a specially crafted web page containing an IFRAME with an overly large “height” attribute viewed using the Apple Safari browser.
Successful exploitation may allow execution of arbitrary code with kernel-mode privileges.
The vulnerability is confirmed on a fully patched Windows 7 Professional 64-bit.
Other versions may also be affected.
Solution:
No effective solution is currently available.
Discovered By:
webDEViL
Original Advisory:
https://twitter.com/#!/w3bd3vil/status/148454992989261824
<iframe height=’18082563′></iframe> causes a BSoD on win 7 x64 via Safari. Lol!
Tags: Bugs, Exploits, Memory Corruption, Memory Corruption Vulnerability, Vulnerabilities, Vulnerability, win32k.sys, win32k.sys Vulnerability, Windows, Windows 7, Windows 7 Vulnerability, Windows Error, Windows Exploit, Windows Vulnerability
Filed in Exploits, Vulnerabilities | Prasanna Sherekar | Comments Off