
A simple flaw , which is present in 28 Antivirus programs, can allow malicious actors to exploit a system and disable the antivirus program.
The bug abuses the directory junctions on Windows and symlinks on macOS and Linux.
An intruder will not need administrator privileges to exploit an Antivirus program on a Windows operating system.
Basically, the way an Antivirus works is by acquiring high privileges to scan all files and directories of a device, to find unknown and malicious files, so that it can move them to an isolated environment.
Due to its nature, Antivirus paves the way for different exploits to malicious actors, who ultimately manage to gain high privileges on a system.
The process of exploiting this vulnerability is relatively simple, especially for an experienced hacker. However, to be successful, it must be done at the right time. If the attacker manages to find the exact moment to carry out their attack, then they can gain access to the system.
Windows Exploitation
Security researchers exploited the vulnerability in McAfee Endpoint Security for Windows and managed to delete the EpSecApiLib.dll, as shown in the video below.
Exploitation macOS & Linux
The researchers also tried to exploit the vulnerability in the Norton Internet Security for macOS and downloaded the EICAR test-string from Pastebin to bypass real-time protection, which prevents the test-string from being downloaded from the official Norton website.
During the download of the test-string from Pastebin, the Antivirus immediately detected the process as malicious software and attempted to stop it.
The researchers managed to exploit Antivirus programs on Linux as well and were able to delete important files.
All affected Antivirus vendors were notified and almost all have already patched this bug in their products.
Users are advised to immediately install the latest update of the Antivirus program they use.
