C
月内に
セキュリティ研究員のNightmare Eclipse氏が、Kaspersky Endpoint SecurityとAvast Antivirusのゼロデイ脆弱…
📌 一言でいうと
セキュリティ研究員のNightmare Eclipse氏が、Kaspersky Endpoint SecurityとAvast Antivirusのゼロデイ脆弱性を公開しました。Kasperskyの脆弱性「HardBreacher」は権限昇格を可能にし、Avastの脆弱性「PrettyPrague」はサンドボックスを悪用してSYSTEM権限のシェルを取得できる可能性があります。Kasperskyは既に修正パッチを配布済みであり、Avastの脆弱性はGen Digital傘下の他製品(AVG, Norton等)にも影響する可能性があります。
🔍該当判定
- 社内で「Kaspersky Endpoint Security(カスペルスキー)」を利用している
- 社内で「Avast Antivirus(アバスト)」を利用している
- 社内で「AVG」または「Norton(ノートン)」のセキュリティソフトを利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Kaspersky製品を利用している場合は、最新の自動更新を適用すること。AvastおよびGen Digital製品を利用している場合は、ベンダーからの修正パッチの提供状況を確認し、速やかに適用すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】KasperskyおよびAvast Antivirusの脆弱性対応について
お疲れさまです。セキュリティ脆弱性に関する情報共有です。
■ 概要
研究員Nightmare Eclipse氏により、Kaspersky Endpoint Security(HardBreacher)およびAvast Antivirus(PrettyPrague)における権限昇格の脆弱性が公開されました。攻撃者がこれらを悪用した場合、システム上の完全な権限(SYSTEM権限)を取得される恐れがあります。
■ 影響範囲
- Kaspersky Endpoint Security
- Avast Antivirus (およびAVG, Norton等のGen Digital製品の可能性あり)
■ 対応手順
1. Kaspersky製品の自動更新を確認し、最新のパッチが適用されているか確認してください。
2. Avast/Gen Digital製品のアップデートを確認し、最新バージョンへ更新してください。
■ 参考情報
- SecurityWeek 報道記事
対応優先度: 高
対応期限: 速やかに
お疲れさまです。セキュリティ脆弱性に関する情報共有です。
■ 概要
研究員Nightmare Eclipse氏により、Kaspersky Endpoint Security(HardBreacher)およびAvast Antivirus(PrettyPrague)における権限昇格の脆弱性が公開されました。攻撃者がこれらを悪用した場合、システム上の完全な権限(SYSTEM権限)を取得される恐れがあります。
■ 影響範囲
- Kaspersky Endpoint Security
- Avast Antivirus (およびAVG, Norton等のGen Digital製品の可能性あり)
■ 対応手順
1. Kaspersky製品の自動更新を確認し、最新のパッチが適用されているか確認してください。
2. Avast/Gen Digital製品のアップデートを確認し、最新バージョンへ更新してください。
■ 参考情報
- SecurityWeek 報道記事
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Vulnerabilities in Kaspersky and Avast Antivirus
Dear IT/Security Team,
We are sharing information regarding recently disclosed vulnerabilities in Kaspersky and Avast security products.
■ Overview
Researcher Nightmare Eclipse has disclosed two zero-day vulnerabilities: 'HardBreacher' in Kaspersky Endpoint Security and 'PrettyPrague' in Avast Antivirus. Both vulnerabilities could allow an attacker to achieve full SYSTEM-level privileges on the affected host.
■ Scope
- Kaspersky Endpoint Security
- Avast Antivirus (potentially affecting other Gen Digital brands such as AVG and Norton)
■ Action Plan
1. Ensure that Kaspersky Endpoint Security is updated via the automatic update mechanism.
2. Check for and apply the latest updates for Avast and other Gen Digital antivirus products.
■ Reference
- SecurityWeek report
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding recently disclosed vulnerabilities in Kaspersky and Avast security products.
■ Overview
Researcher Nightmare Eclipse has disclosed two zero-day vulnerabilities: 'HardBreacher' in Kaspersky Endpoint Security and 'PrettyPrague' in Avast Antivirus. Both vulnerabilities could allow an attacker to achieve full SYSTEM-level privileges on the affected host.
■ Scope
- Kaspersky Endpoint Security
- Avast Antivirus (potentially affecting other Gen Digital brands such as AVG and Norton)
■ Action Plan
1. Ensure that Kaspersky Endpoint Security is updated via the automatic update mechanism.
2. Check for and apply the latest updates for Avast and other Gen Digital antivirus products.
■ Reference
- SecurityWeek report
Priority: High
Deadline: Immediate