Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Geek before it was Chic.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Microsoft Visual C++ 2015-2022 Redistributable Package
6. Sergei Strelec's WinPE
7. Visual C++ Redistributable Runtimes AIO Repack
8. Mozilla Firefox
9. McAfee Removal Tool (MCPR)
10. Tweaking.com - Windows Repair
More >>

top reads

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff


MajorGeeks.Com » News » December 2015 » McAfee, Kaspersky and AVG Anti-virus Softwares Vulnerable

McAfee, Kaspersky and AVG Anti-virus Softwares Vulnerable


Posted by: Timothy Weaver on 12/14/2015 10:41 AM [ comments Comments ]


Kaspersky, McAfee and AVG have all been shown to have a significant vulnerability by enSilo, the Israel-based cyber-security startup.

The flaw includes AVG Internet Security 2015, McAfee VirusScan Enterprise version 8.8 and Kaspersky Total Security 2015.

These giants of the enterprise antivirus software game were all subject to the same coding issue. The softwares would allocate memory for read and write, as well as execute permissions with an address that an attacker could easily predict and then proceed to inject code into the target system.

Tomer Bitton, vice president of research at enSilo, wrote in a recent blog post, “The enSilo product alerted on a product collision with AVG, also installed in the customer's environment. A follow-up investigation conducted by our researchers revealed a flaw in AVG.”

Bitton described what he saw as the essential problem: “The anti-virus companies adopted a coding malpractice which essentially defeats Windows' mitigations against application exploitation.” This meant that the anti-virus products could conceivably become an “attacker's vehicle into taking complete control of the underlying Windows system”.

enSilo has released a tool that will tell if a system is vulnerable. Bitton said that the problem probably is not isolated to anti-virus software: “Due to the prevalence of this issue in anti-virus products, we can assume that this issue is replicated across other intrusive applications.”

Kaspersky said that they had released a patch in September. “The vulnerability couldn't be exploited by itself with code execution and privilege escalation, but could have simplified the exploitation of 3rd party application vulnerabilities, such as stack based buffer-overflow,” it said.

McAfee also commented that, "Intel Security takes the integrity of our products very seriously. Upon learning of this particular issue, we quickly evaluated the researchers' claims and took action to develop and distribute a solution addressing it. This solution was distributed to customers in a patch on August 26, 2015. We are not aware of any customers targeted with an exploit of the issue in question."

Source: SCMagazine


« 10 Luxury Golf Carts That Will Blow Your Mind @ Worthly · McAfee, Kaspersky and AVG Anti-virus Softwares Vulnerable · Pedo hunt' Lee Philip Rees Sentenced to Nine Years »




Comments
comments powered by Disqus

MajorGeeks.Com » News » December 2015 » McAfee, Kaspersky and AVG Anti-virus Softwares Vulnerable

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition