October 4, 2005 12:27 PM PDT

Kaspersky confirms antivirus software flaw

Kaspersky Lab confirmed Tuesday that a potentially serious flaw exists in its antivirus software, but said a fix is on the way.

The security software maker said it had offered preliminary protection to customers last week and that a permanent patch will be available on Wednesday.

Kaspersky also said that the vulnerability is limited to Microsoft Windows-based versions of its products. Additionally, while it does license the vulnerable component to some third parties, most partner products that use Kaspersky code are not affected, the Moscow-based company said in a statement.

Kaspersky issued the statement in response to a report on Monday of a flaw in its antivirus library. An attacker could exploit the heap overflow vulnerability to commandeer systems that run Kaspersky's products, security researcher Alex Wheeler wrote in an advisory (download PDF).

"The actual threat posed by the...vulnerability is minimal and cannot affect the level of antivirus protection provided by Kaspersky Lab products," the company said in the statement.

Wheeler informed Kaspersky of the flaw around Sept. 24, said Stephen Orenberg, president of Kaspersky's North American operations. After an initial investigation, Kaspersky provided updated antivirus signatures on Sept. 29 to protect customers against attacks exploiting the flaw, he said. A final fix is due Wednesday, Orenberg said.

Affected products are: Kaspersky Anti-Virus Personal 5.0; Kaspersky Anti-Virus Personal Pro 5.0; Kaspersky Anti-Virus 5.0 for Windows Workstations; Kaspersky Anti-Virus 5.0 for Windows File Servers and Kaspersky Personal Security Suite 1.1.

"This is a theoretical flaw," Orenberg said. "There has never been an exploit for this flaw."

A hacker could launch a remote attack via the vulnerability by sending a malformed CAB file to a PC--in an e-mail, for example, the French Security Incident Response Team said in an advisory Monday. No user interaction is needed for the malicious code to run, FrSirt noted. The group gave the issue its highest rating of "critical."

As the pool of easily exploitable security bugs in Microsoft Windows dries up, attackers are looking for holes in security software as a way to get into systems, Yankee Group analysts wrote in a research paper released earlier this year.

At the Black Hat Briefings security conference this summer, researchers at Internet Security Systems outlined vulnerabilities in antivirus products. ISS has discovered bugs in products from security software makers including Symantec, McAfee, Trend Micro and F-Secure.

4 comments

Join the conversation!
Add your comment (Log in or register)
Kaspersky wouldn't work on my system anyway.
Went looking for a replacement for over the hill resource hog Norton AV. Kaspersky demo wouldn't even load properly. AVG anti-virus works, and it works so well.
Posted by (62 comments )
Reply Link Flag
Kaspersky wouldn't work on my system anyway.
Went looking for a replacement for over the hill resource hog Norton AV. Kaspersky demo wouldn't even load properly. AVG anti-virus works, and it works so well.
Posted by (62 comments )
Reply Link Flag
This is terrible news for consumers looking for security.
Posted by antivirus-software (27 comments )
Reply Link Flag
The Kaspersky Security fails to install ,due to remains of "McAfee Internet Security With Site Advisor 2008 " that still active in the system,after all unistalling / cleaning procedures.............
Posted by moncho55 (4 comments )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Computer Associates International Inc. (-1.53%) -0.42 26.72
Dow Jones Industrials (-0.69%) -89.23 12,801.23
S&P 500 (-0.69%) -9.31 1,342.64
NASDAQ (-0.80%) -23.35 2,903.88
CNET TECH (-0.58%) -11.91 2,032.01
  Symbol Lookup