Kaspersky Antivirus UPX Parsing Remote Memory Corruption

While fuzzing UPX packed files in Kaspersky Antivirus, a crash was discovered resulting in an arbitrary stack-relative write. This vulnerability is obviously remotely exploitable for remote code execution as NT AUTHORITYSYSTEM.

Leave a Reply