Kaspersky Total Security features Security Restriction Bypass Vulnerability (CVE-2015-8579)
Kaspersky Total Security features Security Restriction Bypass Vulnerability (CVE-2015-8579)
Release date:
Updated on:
Affected Systems:
Kaspersky Labs Total Security 2015 15.0.2.361
Description:
CVE (CAN) ID: CVE-2015-8579
Kaspersky Total Security is anti-virus Internet Security software.
Kaspersky Total Security 2015 15.0.2.361 protects user-mode processes by allocating RWX-authorized memory on foreseeable addresses. This allows remote attackers to bypass the DEP and ASLR protection mechanisms.
<* Source: annoymous
*>
Suggestion:
Vendor patch:
McAfee
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://breakingmalware.com/vulnerabilities/sedating-watchdog-abusing-security-products-bypass-mitigations/
Http://blog.ensilo.com/the-av-vulnerability-that-bypasses-mitigations
This article permanently updates the link address: