An analysis of the code emulator feature used in ESET products showed that it was not robust enough and could be easily compromised, allowing an attacker to take full control of a system running the vulnerable security solution.
The code emulator is integrated into the company's antivirus products and allows files or scripts to be executed before the user does. This process occurs in an isolated environment so that the real system cannot be affected.
The collected data is provided to the software's heuristic analyzer, which decides whether its nature indicates malicious or suspicious software.
Researcher Tavis Ormandy from Google Project Zero discovered the vulnerability in NOD32 Antivirus, but as he reports, other products are also affected, across all versions (Windows, OS X and Linux), as well as Endpoint and Business editions.
“Many antivirus products have emulation capabilities. ESET NOD32 uses a microfilter or kext (the name comes from kernel extension) to monitor Disk I/O,” says Ormandy.
Because Disk I/O operations can be triggered in various ways, malicious code can be passed to the disk, from messages, files, images, or other types of data. Hence the need for a robust and properly isolated code emulator in antivirus solutions.
Ormandy found the glitch, analyzed it, and created a remote root exploit in a few days, reporting that it can achieve full access to the victim's system.
However, it should be noted that Ormandy reported the vulnerability to ESET on June 18th and the company immediately released an updated version for the scanning engine (just 4 days later).
You can find more technical details about the vulnerability, including the exploit, on the vulnerability announcement page
