Windows bug can raise privileges
A newly discovered flaw in Kaspersky Antivirus for Endpoint lets a local attacker gain higher-level control over your Windows PC. This could let them run commands as an admin without your permission.
- Report priority
- High
- Involves
- Kaspersky Antivirus for Endpoint
What is known
An attacker with physical or remote access to your PC sends a specially crafted request to Kaspersky Antivirus for Endpoint, tricking it into giving them elevated permissions.
What to do
Check if you're using Kaspersky Antivirus for Endpoint by opening the app and looking for its version number in the About or version screen.
Update to the latest version of Kaspersky Antivirus for Endpoint immediately, as the vendor has not yet confirmed a fix but warns this is a serious risk.
Reported details
An attacker with access to your Windows machine sends a hidden command to Kaspersky Antivirus for Endpoint. The antivirus misinterprets it as a normal request and grants the attacker admin-level control. The attacker then uses that access to install malware or steal data without you noticing.
A local privilege escalation vulnerability in Kaspersky Antivirus for Endpoint (tracked as NEWS-f3e8cae2530154d5fa) allows an attacker with local access to elevate their privileges and gain control over a high-trust system component. The flaw was demonstrated via a proof-of-concept exploit published by GitHub user MSNightmare, though Kaspersky has not yet confirmed or patched the issue. No specific versions are mentioned in the disclosure.