HomeSecurityCritical bug in McAfee allowed Antivirus to be disabled

Critical bug in McAfee allowed antivirus to be disabled

-Intel Security has fixed a dangerous bug in McAfee that allowed attackers to disable Antivirus protection features

-The security flaw remained active for at least 15 months

McAfee
Intel Security, the company behind the popular McAfee Enterprise, has released an updated version of the software, which fixes a critical security flaw that could allow an attacker to disable the antivirus on a victim's computer.

According to Agazzini Maurizio, a researcher at security consultancy Mediaservice, with very simple steps , the protection functions of McAfee VirusScan Enterprise could be disabled, allowing attackers to install malicious software on users' systems.

The vulnerability lies in a feature that was added to the McAfee VirusScan engine to prevent local users from inadvertently making any changes to its normal operation.

Attackers can bypass McAfee administrator password and disable antivirus

By default, the antivirus uses a password that administrators are required to enter in order to disable the engine, and therefore the protection functions of McAfee VirusScan.

Mr. Maurizio discovered that this feature has not been implemented correctly, allowing attackers to bypass the administrator password.

“The McAfee VirusScan console checks the password and asks the program engine for authorization to unlock the secure registry keys,” Maurizio explains on the Mediaservice website. “However, no checks are performed by the engine itself, so anyone can immediately tell the engine to stop, without even knowing the correct administrator password.”.

Additionally, the researcher created a tool that automatically changes the required registry keys so that the attacker can disable the antivirus without entering the password.

Considering how easy it is to automate the entire process via PowerShell commands, the attack opens a big hole in McAfee's defenses.

The researcher adds that this threat is only present if the attacker manages to gain administrator rights on an infected machine. Otherwise, the attack cannot be carried out.

[alert variation=”alert-success”]Users with the Enterprise version of McAfee VirusScan should upgrade to update SB10151 to address the issue. All versions of VirusScan Enterprise prior to version 8.8 are affected by the vulnerability.[/alert]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS