HomeSecurityAntivirus engines affected by code hooking vulnerability

Antivirus engines affected by code hooking vulnerability

Six vulnerabilities in the way some software vendors use the “code hooking” technique expose their products to exploitation by malware that can leverage these security gaps to bypass security mitigations and compromise targeted devices.

Hooking is a coding technique that allows one application to interfere with the process of another application. Many types of desktop applications allow and use it , and in particular, security products that need to monitor other applications for malicious activity.

Antivirus engines affected by code hooking vulnerability

Security firm enSilo has discovered a problem with how a large number of software applications use the code hooking technique, which leaves a door open for exploitation by malicious actors.

Their research stems from previous research that identified problems in the way AVG, McAfee, and Kaspersky handle computer memory space.

It is during this research that the enSilo team noticed the problematic way in which antivirus mechanisms combine with other applications and system APIs to monitor and scan for malicious activity.

Later, they discovered that other types of applications, such as virtualization and software performance monitoring, are vulnerable to the same issue and can be exploited by some malware in attacks that aim to bypass security software and OS-level malware mitigation techniques.

According to enSilo, the following companies have been notified and have begun patching their products: AVG, Kaspersky, McAfee, Symantec, BitDefender, Citrix XenDesktop, Webroot, Emsisoft, Vera, and Avast.

Additionally, any application that uses the Microsoft Detours hooking engine is also affected. This includes a huge list of products from over 100 ISVs (independent software vendors), along with almost all Microsoft products, such as the Office suite.

Patching all applications involves recompiling all affected products and distributing new versions, which explains why enSilo waited so long to publicize these issues.

Microsoft has stated that it will update its applications and Detours engine on  August Patch Tuesday.

Meanwhile, the researchers are set to present their findings at this year's Black Hat security conference, scheduled to take place in Las Vegas in early August. A more technical explanation can be read here, written by Udi Yavo and Tomer Bitton of enSilo.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS