HomeinetVulnerabilities in Kaspersky ATM software

Vulnerabilities in Kaspersky ATM software

A researcher discovered vulnerabilities in the security software of Kaspersky Lab that is used in cash machines and other systems. Hackers can exploit the vulnerabilities to bypass ATM system defenses.

Although Kaspersky responded promptly to the discovery, developed and released a patch, one wonders how long it will take for the updates to be installed on ATM located around the world.Kaspersky

Georgy Zaytsev, a researcher at Positive Technologies, discovered a vulnerability in the application launch control component of Kaspersky Embedded Systems Security 1.1 and 1.2 during a security audit of cash registers using the technology.

The exploitation of the flaw causes Kaspersky's software to become overloaded to a point where it cannot process file verification requests. This means that any malicious software could bypass the white list checks that exist to prevent infections.

“The vulnerabilities that have been reported to us do not immediately allow cash withdrawal from the ATM. Several conditions will need to be met for such an attack to work: for example, before exploiting these vulnerabilities, an intruder must first infect the system with malicious software (bypassing all protection elements) and run it within the system”, said a spokesperson for Kaspersky Lab.

To crash the antivirus, an attacker would need to add a large amount of arbitrary data with an executable file. When this program starts, the system calculates its hash and checks a list of approved digital signatures to decide whether to allow or block the execution of the application. With such a large file, the process takes longer than the time allocated for verifying normal files.

When this time period expires, the program starts anyway. It is a one-time attack, because the hashing process does not stop and the system stores hidden signatures. Therefore, the next time the executable file starts, Kaspersky's software will be able to immediately recognize that the file is malicious and stop it.

If in your service you use Kaspersky programs on ATMs, watch out for the critical fix KB13520. The upgrade was quietly released at the end of June. Thus all ATM owners must promptly update their security software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS