PT-2019-2038 · Kaspersky · Kaspersky Antivirus Engine+1

Publicado

2019-03-26

·

Atualizado

2020-08-24

·

CVE-2019-8285

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kaspersky Lab Antivirus Engine versions prior to 04.apr.2019
Description The issue is related to a heap-based buffer overflow vulnerability in the JS file handler of Kaspersky's antivirus protection. This vulnerability can be exploited by a remote attacker to execute arbitrary code with system privileges. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 04.apr.2019, update the Kaspersky Lab Antivirus Engine to a version released on or after 04.apr.2019 to resolve the issue. As a temporary workaround, consider restricting the scanning of JS files until the update is applied.

Correção

Memory Corruption

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01783
CVE-2019-8285

Produtos afetados

Kaspersky Antivirus Engine
Kaspersky Secure Mail Gateway