Home→Descriptions→SA27187
| Secunia ID | |
| CVE-ID | |
| Release Date |
11 Oct 2007 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Kaspersky Online Scanner 5.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in Kaspersky Online Scanner, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a format string error in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) when processing arguments passed to certain unspecified methods. This can be exploited to execute arbitrary code when a user e.g. visits a malicious website. The vulnerability affects versions 5.0.93.1 and prior. |
| Solution |
Update to version 5.0.98.0. |
| Reported by |
Discovered by Stephen Fewer of Harmony Security and reported via iDefense Labs. |
| Original Advisory |
Kaspersky: iDefense Labs: |