Kaspersky Lab Software Vulnerable to Attack: Report
Users of Kaspersky Lab's Internet Security 2013 software are being told the product contains a bug that, if exploited, could cause their operating system to freeze up.
According to reports, the bug can be exploited by hackers using an Internet Protocol version 6 (IPv6) packet. If a specially-crafted packet is sent to computers running Kaspersky Internet Security 2013 software, a system can be disabled.
"A fragmented packet with multiple but one large extension header leads to a complete freeze of the operating system," said security expert Marc Heuse. "No log message or warning window is generated, nor is the system able to perform any task." (Source: pcworld.com)
Kaspersky Lab Slow to Respond
Luckily IPv6 Internet adoption rates are relatively low. However, because many computers can be accessed via IPv6 on local networks, the threat remains substantial.
Heuse says he discovered the flaw in January 2013. He reported the issue to Kaspersky Lab late that month, but received no reply. He again sent a message to Kaspersky Lab in mid-February but again did not hear back from the Russian security company.
In an attempt to draw Kaspersky's attention to the issue, Heuse later published a proof-of-concept tool that could be used to exploit the flaw.
Automatic Patch Coming Soon
Kaspersky Lab has finally acknowledged that the threat exists. The firm also says it is actively developing a patch that will "fix the problem automatically on every computer protected by Kaspersky Internet Security 2013."
It remains unclear when Kaspersky Lab will make the automatic patch available to home users.
In the meantime, Kaspersky insists that the threat posed to the average Kaspersky Internet Security 2013 user is minimal.
Furthermore, the firm says that "Kaspersky Lab would like to apologize for any inconvenience caused. Actions have been taken to prevent such incidents from occurring in the future." (Source: zdnet.com)
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.