A vulnerability that could be exploited by attackers was discovered and quickly patched in the Kaspersky Internet Security antivirus suite.
A vulnerability that allowed hackers to spoof traffic and use the antivirus product against the user and the product itself.
Google Project Zero security researcher Tavis Ormandy has had a string of successes these days, finding zero-day vulnerabilities in the same Kaspersky antivirus in early September, and then another one in Avast antivirus just last week.
Now he turned his attention to the Kaspersky Internet Security package and more specifically to the Network Attack Blocker, a feature that protects computers from malware and other attacks based on the Internet or a local network for propaganda.
According to Mr. Ormandy's research, the problem is actually a design flaw, in the Network Attack Blocker which is "a simple filter with a pattern signature system to match it."
This means that the component scans each network packet in turn and does not track whether the system it comes from has already been cleared.
Antivirus could have been used to block Windows upgrades
If a malicious packet is detected trying to intrude, Kaspersky antivirus simply blacklists the source IP address of that packet.
As Mr. Ormandy explains, an attacker could easily forge a network packet, and then trick the antivirus into blocking services such as Windows Update, Kaspersky's own update servers, or any other IPs which could cripple the computer's defenses, allowing them to launch new attacks later.
Furthermore, because Network Attack Blocker does not understand the broader context (application layer), the antivirus can also be tricked into blocking IP addresses by simply embedding a virus signature in an image's metadata, or within an email message.
The vulnerability was discovered and reported to Kaspersky on September 11, and the security vendor issued a fix on October 8

