enSilo: Some of the biggest names in the security software space can be compromised by a serious vulnerability that allows a hacker to use a commercial security code to infiltrate computers.
In March, researchers from the Israeli security company enSilo discovered a serious flaw in the free security application AVG Internet Security 2015. They determined that the software allocated memory permissions for reading, writing and execution (RWX) to a predictable address that an attacker could use to inject malicious code into a target system.
The company enSilο got in touch with AVG and the bug was fixed within the next few days. However, the company continued the research on other security suites and found that McAfee VirusScan Enterprise version 8.8 and Kaspersky Total Security 2015 were also vulnerable.
“We will continue to update this list as we have more information,” Tomer Bitton, VP of enSilo, said in a post.
“This error is a recurring encoding issue of the Anti-Virus. We believe that this vulnerability is also likely to appear in other popular products that are not related to security.”
Due to the potentially widespread nature of the problem, enSilo created a free checking tool called AVulnerabilityChecker. The tool is available on Github for anyone who wishes to use it.
https://github.com/BreakingMalware/AVulnerabilityChecker
Intel, the parent company of McAfee, and Kaspersky have already fixed the vulnerability.
So every user of the aforementioned products must download and install all the latest updates.
