Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re[2]: Kaspersky AntiVirus Window Caption GUI Bypass Vulnerability

Re[2]: Kaspersky AntiVirus Window Caption GUI Bypass Vulnerability

From: 3APA3A <3APA3A_at_SECURITY.NNOV.RU>
Date: Wed, 6 Oct 2004 15:17:58 +0400

Dear Simon,

--Tuesday, October 5, 2004, 11:03:16 PM, you wrote to miguel.dilaj_at_pharma.novartis.com:

>>
S> Looks like a usability versus security issue, where usability takes
S> priority.

In this very case issue is too serious (by accessing password protected
functions in Kaspersky Antivirus user can schedule his own task to run
with LocalSystem privileges). This is good old design flow again: user's
privileges are checked by client component only.

-- 
~/ZARAZA
Стреляя во второй раз, он искалечил постороннего. Посторонним был я. (Твен)
Received on Oct 06 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos