HomeSecurityAvast: Disables antivirus JavaScript engine due to vulnerability

Avast: Disables antivirus JavaScript engine due to vulnerability

Czech antivirus software maker Avast has made a drastic decision to disable a key component of its antivirus product after discovering a dangerous vulnerability that puts all of the company's users at risk .

The vulnerability was found in Avast's JavaScript engine, an internal component of Avast antivirus thatanalyzes JavaScript code for malwarebefore it is allowed to run in browsers or email clients.

"Despite the fact that it processes untrusted inputs, it is unsandboxed," said Tavis Ormandy, a security researcher at Google.

"Any vulnerabilities in this process are critical and can be exploited by remote attackers," Ormandy said on Monday, when he released a toolhe used to analyze the antivirus .

Exploiting the vulnerability was an easy process

Exploiting this vulnerability is very simple. All it takes is sending a malicious JS or WSH file to a user via email or tricking a user into opening a file with malicious JavaScript code.

According to Ormandy, once Avast antivirus downloads and executes the malicious JavaScript code within its own custom engine, malicious operations will begin to be performed on the victim's computer, while the remote attacker will gain full access to the system.

For example, exploiting this vulnerability could allow an attacker to install malware on an Avast antivirus user's device

Avast: Disables antivirus JavaScript engine due to vulnerability

Avast learned about the vulnerability recently

Avast was notified of the vulnerability almost a week ago. However, the companyhas not yet released a patch to fix the bug. What it has done is disable the JavaScript detection capabilities of its antivirus until a patch is ready.

The Czech company made the following statement:

“Last Wednesday, March 4, Google researcher Tavis Ormandy reported that there is a vulnerability in our. The vulnerability could potentially be used to execute malicious code remotely. On March 9, a tool was released to simplify vulnerability analysis.”.

According to Avast, some measures have been taken to mitigate the risk so that the company's millions of users are not affected and remain protected from potential attacks . The company believes that the functionality of its antivirus product will not be affected, since it relies on multiple layers of security.

The patch's release date has not yet been announced.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS