|
Brought to you by:
Suppliers of:
|
|
|
| |
| Insecure permissions have been detected in the multiple Kaspersky Lab antivirus products. |
| |
Credit:
The information has been provided by Maxim A. Kulakov .
|
| |
Vulnerable Systems:
* Kaspersky Anti-Virus 5.0 for Windows Workstations (5.0.712)
* Kaspersky Antivirus Personal 5.0.x
* Kaspersky Anti-Virus 6.0 for Windows Workstations (6.0.3.837)
* Kaspersky Anti-Virus 6.0 for Windows File Servers (6.0.3.837)
* Kaspersky Anti-Virus 7 (7.0.1.325)
* Kaspersky Anti-Virus 2009 (8.0.0.x)
* Kaspersky Anti-Virus 2010 (9.0.0.463)
* Kaspersky Internet Security 7 (7.0.1.325)
* Kaspersky Internet Security 2009 (8.0.0.x)
* Kaspersky Internet Security 2010 (9.0.0.463)
Immune Systems:
* Kaspersky Anti-Virus 2010 (9.0.0.736)
* Kaspersky Internet Security 2010 (9.0.0.736)
* Kaspersky Anti-Virus 6.0 for Windows Workstations (6.0.4.1212)
* Kaspersky Anti-Virus 6.0 for Windows File Servers (6.0.4.1212)
Everyone" group has Full Control rights to the BASES folder. The folder consists of antivirus bases, configuration files and executable modules.
Local attacker (unprivileged user) can replace some files (for example, executable modules) by malicious file and execute arbitrary code with SYSTEM privileges. This is local privilege escalation vulnerability.
For example, in Kaspersky Anti-Virus 2010 (9.0.0.463) the following attack scenario could be used:
1. An attacker (unprivileged user) replaces one of the *.kdl files by malicious dynamic link library (DLL). The replacing file could be - %ALLUSERSPROFILE%\Application Data\Kaspersky Lab\AVP9\Bases\vulns.kdl.
2. Restart the system.
After restart attackers malicious DLL will be loaded with SYSTEM privileges.
Self-defense of the Kaspersky Anti-Virus will prevent all operations with own files. It can be bypassed using internal shell dialogs in Kaspersky Anti-Virus (for example, "Open" dialog in Quarantine).
For other vulnerable Kaspersky Lab products similar attack scenario could be used.
An attacker must have valid logon credentials to a system where vulnerable software is installed.
Disclosure Timeline:
16/07/2009 Initial vendor notification. Secure contacts requested.
16/07/2009 Vendor response
01/10/2009 Corporate product line has been updated (Kaspersky Anti-Virus for Windows Workstations 6.0.4.1212 released)
22/10/2009 Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 Critical Fix 2 released
16/12/2009 Advisory released
|
|
|
|
|