Slashdot Mirror


Kaspersky Fixes Bug That Allowed Attackers To Block Windows Update & Others (softpedia.com)

An anonymous reader writes with this story at Softpedia about Google Project Zero security researcher Tavis Ormandy's latest find. A vulnerability that allowed abuse by attackers was discovered and quickly fixed in the Kaspersky Internet Security antivirus package, one which allowed hackers to spoof traffic and use the antivirus product against the user and itself. Basically, by spoofing a few TCP packets, attackers could have tricked the antivirus into blocking services like Windows Update, Kaspersky's own update servers, or any other IPs which might cripple a computer's defenses, allowing them to carry out further attacks later on.

1 of 34 comments (clear)

  1. Block Windows Update? by Anonymous Coward · · Score: 1, Interesting

    Thank you hackers!!!