Search This Blog

Tuesday, July 24, 2007

[NEWS] Kaspersky Antivirus License Protection Vulnerability

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Kaspersky Antivirus License Protection Vulnerability
------------------------------------------------------------------------


SUMMARY

Kaspersky Antivirus license protection can be used to disable the
antivirus's functionality if the date of the machine is set to that of an
eariler date than that of the license. Malicious software can use this
method to disable the antivirus by simply changing the date a year back
(for example).

DETAILS

You can cause the Kaspersky antivirus to switch off by changing the year
value in date back one year.

For example:
c:\> date 24.07.2006

Vendor Status:
* 2006-06-15 - Vendor notified via Russian forum
* 2006-06-15 - Vendor replied via forum (private message)
* 2007-07-09 - Vendor asked via forum and VIP-Support
* 2007-07-09 - Vendor replied "
<http://forum.kaspersky.com/index.php?showtopic=42889> Issue - 26328"


ADDITIONAL INFORMATION

The information has been provided by <mailto:imiturin@russlavbank.com>
Igor U.Miturin.

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

No comments: