PT-2004-1961 · Kaspersky · Kaspersky+1

Published

2004-11-19

·

Updated

2021-04-09

·

CVE-2004-0934

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Kaspersky versions 3.x through 4.x
Description: The issue allows remote attackers to bypass antivirus protection. This is achieved by using a compressed file with both local and global headers set to zero. Despite the headers being set to zero, the compressed file can still be opened on a target system, thus bypassing the protection.
Recommendations: For versions 3.x through 4.x, as a temporary workaround, consider restricting the opening of compressed files with altered headers until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0934

Affected Products

Kaspersky
Kaspersky Anti-Virus