Kaspersky Antivirus Yoda's Protector Unpacking Remote Memory Corruption

The attached testcase was found by fuzzing packed PE files with Kaspersky Antivirus. The researcher suspects it was packed using “Yoda’s protector”. This vulnerability is obviously exploitable for remote code execution as NT AUTHORITYSYSTEM on all systems using Kaspersky Antivirus.

Leave a Reply