First published: Wed Dec 31 2003(Updated: )
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | =4.0.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1443 has a severity level that indicates a significant risk due to the ability of local users to bypass virus protection.
To fix CVE-2003-1443, upgrade Kaspersky Anti-Virus to a version later than 4.0.9.0 that addresses this vulnerability.
CVE-2003-1443 affects users of Kaspersky Anti-Virus version 4.0.9.0.
CVE-2003-1443 exploits the inability of Kaspersky Anti-Virus to detect viruses in files named with MS-DOS device names.
To enhance security against CVE-2003-1443, ensure that Kaspersky Anti-Virus is updated regularly and monitor for any abnormal file behavior.