First published: Fri Jan 06 2017(Updated: )
A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus 2010 | =16.0.0.614 | |
Kaspersky Internet Security 2010 | =16.0.0.614 | |
Kaspersky Total Security 2015 | =16.0.0.614 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4329 is classified as a local denial of service vulnerability.
To fix CVE-2016-4329, users should update their Kaspersky Anti-Virus software to the latest version available.
CVE-2016-4329 affects Kaspersky Anti-Virus, Kaspersky Internet Security, and Kaspersky Total Security, all version 16.0.0.614.
No, CVE-2016-4329 is a local vulnerability and requires direct access to the affected system.
Exploiting CVE-2016-4329 can cause the affected Kaspersky application to terminate, which may bypass self-protection mechanisms.