CVE-2003-1443: Input Validation
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1443?
CVE-2003-1443 has a severity level that indicates a significant risk due to the ability of local users to bypass virus protection.
How do I fix CVE-2003-1443?
To fix CVE-2003-1443, upgrade Kaspersky Anti-Virus to a version later than 4.0.9.0 that addresses this vulnerability.
Who is affected by CVE-2003-1443?
CVE-2003-1443 affects users of Kaspersky Anti-Virus version 4.0.9.0.
What does CVE-2003-1443 exploit?
CVE-2003-1443 exploits the inability of Kaspersky Anti-Virus to detect viruses in files named with MS-DOS device names.
What can I do to enhance security against CVE-2003-1443?
To enhance security against CVE-2003-1443, ensure that Kaspersky Anti-Virus is updated regularly and monitor for any abnormal file behavior.