Kaspersky Antivirus DEX File Format Memory Corruption
Posted by deepcore on November 17, 2015 – 4:17 pm
The attached testcase was found by fuzzing DEX files, and results in a heap overflow with a wild memcpy. Note that Kaspersky catch exceptions and continue execution, so running into unmapped pages doesn’t terminate the process, this should make exploitation quite realistic.
Post a reply
You must be logged in to post a comment.