Researchers have discovered a serious remote code execution vulnerability affecting products from Kaspersky Lab. The cybersecurity firm pushed out a patch to customers in early April.
The flaw, tracked as CVE-2019-8285 and assigned a CVSS score of 8.0, was reported to Kaspersky by researchers from a team called “Imaginary.” The experts found a way to remotely execute arbitrary code by exploiting a heap-based buffer overflow.
According to Kaspersky, which pushed out a patch on April 4 via a product update, software using antivirus databases was impacted.
Third-party advisories said the flaw existed in the company’s antivirus engine and they listed several impacted versions of Kaspersky Antivirus.
Germany’s Federal Office for Information Security (BSI) last week published an alert to warn users. Kaspersky’s advisory was also made public last week.