Researchers have discovered a serious remote code execution vulnerability affecting products from Kaspersky Lab. The cybersecurity firm pushed out a patch to customers in early April.
The flaw, tracked as CVE-2019-8285 and assigned a CVSS score of 8.0, was reported to Kaspersky by researchers from a team called “Imaginary.” The experts found a way to remotely execute arbitrary code by exploiting a heap-based buffer overflow.
According to Kaspersky, which pushed out a patch on April 4 via a product update, software using antivirus databases was impacted.
Third-party advisories said the flaw existed in the company’s antivirus engine and they listed several impacted versions of Kaspersky Antivirus.
Germany’s Federal Office for Information Security (BSI) last week published an alert to warn users. Kaspersky’s advisory was also made public last week.
Related: Check Point ZoneAlarm Flaw Allows Privilege Escalation
Related: Flaw in ESET Antivirus for Mac Allowed Code Execution
Related: Antivirus Quarantine Flaws Allow Privilege Escalation
Related: Google Researcher Finds Certificate Flaws in Kaspersky Products