Risk: High
Independent researcher Alex Wheeler has reported a vulnerability in Kaspersky Anti-Virus, which can be exploited by attackers to compromise a vulnerable system.
The vulnerability is caused due to a boundary error in "cab.ppl" when processing malformed CAB archives. This can be exploited to cause a heap-based buffer overflow and allows arbitrary code execution when a malicious CAB archive is scanned.