Saturday, September 11th 2010, 4:43am UTC+2

You are not logged in.

Dear visitor, welcome to AV-Comparatives Forum. If this is your first visit here, please read the Help. It explains how this page works. You must be registered before you can use all the page's features. Please use the registration form, to register here or read more information about the registration process. If you are already registered, please login here.

1

Monday, February 1st 2010, 3:45pm

Microsoft AVI File Exploit Lets Users Crash Programs such as Anti Viruses and Anti Rootkits

Microsoft AVI File Exploit Lets Local Users Crash Windows Applications (Even Protected Programs such as Anti Viruses and Anti Rootkits)
Vulnerability Info:

Type: Crash / Exploit

Risk: High

Fix Available: No

Version(s): 2k SP4, 2k3 SP2, XP SP2, SP3 - Vista and 7 safe.

Description: an AVI file with manipulate data will crash the windows Programs, when a local user open a Directory form his/her Program to open the target file contain a manipulate AVI file, Target Program will crash and terminate.
Also when you click on selected file windows explorer will crash too.

Impact: A remote or local user could crash the target windows Programs like windows Explorer or even anti viruses and anti root kits.

Vendor Confirmed: Not yet

Exploit able: yes

We demonstrate some Video for Anti Viruses and Anti Rootkits here:
AVG_9.0
Avira Antivir
BitDefender_2009
Kaspersky_Inernet_Security_2010
Rootkit_Unhooker_LE_V3.8

You can download Vulnerability Video here

Watch this video

http://www.u0vd.org/avi.zip

Best Regards,

www.u0vd.org

Location: England, London

2

Friday, February 5th 2010, 6:19pm

Wow, very interesting exploit.

Just out of curiosity, why the Kaspersky video is in Safe Mode.
What are Kaspersky's effects when it is fully functional with default settings in normal mode, like conditions the other AVs were tried in?

3

Saturday, February 6th 2010, 7:56am

Doesn’t matter

Doesn’t matter if you run kasper or other anti viruses or anti Rootkits in normal mode or safe mode, this Vulnerability always work !

We just want show this.

Regards,

Rate this thread