A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92771 | vdb entry |
http://www.talosintelligence.com/reports/TALOS-2016-0175/ | exploit vdb entry third party advisory technical description |
http://www.securityfocus.com/bid/92771/info | third party advisory vdb entry |
https://support.kaspersky.com/vulnerability.aspx?el=12430#010916 | vendor advisory |