HomeSecurityGoogle researcher finds security flaw in Symantec Antivirus

Google researcher finds security flaw in Symantec Antivirus

Tavis Ormandy, a security researcher working on Google's Project Zero, discovered and helped Symantec fix a serious security issue that affected the Symantec Antivirus Engine and the core of many of the company's security products.

Ormandy explains that, in some cases, when certain types of data reach the Symantec Antivirus Engine (SAE), the product handles these files in an unsafe manner that leads to a buffer overflow.

Google researcher finds security flaw in Symantec Antivirus

"When parsing executables are imported into an early version of aspack, a buffer overflow can occur in the Symantec Antivirus Engine core used in most Symantec and Norton Antivirus products," says Ormandy. "The problem occurs when a piece of data is truncated, that is, when SizeOfRawData is larger than SizeOfImage."

This crashes the security mechanism in a non-standard way, which then grants root privileges to the attacker, allowing them to execute code on the computer. The security issue, which carries the identifier CVE-2016-2208, affects all operating systems: Mac, Linux , and Windows.

Ormandy says the issue can be exploited in a very simple way. Because the flaw lies in the detection mechanism itself, which opens and reads ANY file, not just the one the user has selected for scanning, the attacker can simply send an exploit via email or a link to an exploit on the Web.

The mechanism will scan its content automatically and compromise the user's machine, without requiring user interaction.

On Windows computers, Ormandy says this is even more of an issue, since the scanning engine runs directly in the Windows.

Exploiting this flaw in Windows leads to the corruption of Ring 0 of the kernel, the most privileged layer of the operating system that interacts most directly with physical hardware, such as the CPU and memory. This leads to a "kernel panic" condition, which can sometimes lead to a BSOD (Blue Screen of Death).

CVE-2016-2208 affects the company's products, including Symantec Endpoint Antivirus, Norton Antivirus, Symantec Scan Engine, and Symantec Email Security. Ormandy says that, theoretically, the flaw could also affect any other product where Symantec used SAE.

The researcher disclosed the problem to Symantec, and the company released a patch that customers can download and apply to their software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS