The popular AVG Secure Search Toolbar, which is provided by AVG Technologies and is supposed to protect users from malicious websites, has been found to be unsafe, as it could allow arbitrary code execution by a potential attacker.
This toolbar, also known as AVG SafeGuard, is offered as an optional installation with popular, free software programs.
According to researchers at Carnegie Mellon University's Computer Emergency Response Team (CERT/CC), version 18.1.6 of AVG Secure Search and AVG SafeGuard, as well as earlier versions, install an ActiveX control called ScriptHelperApi in Internet Explorer, which uses unsafe methods to operate.
“This ActiveX control has been marked as “Safe for Scripting” in Internet Explorer, meaning it cannot be reconfigured by an attacker. Because this control does not internally enforce any restrictions on which sites can call its methods (such as by using the SiteLock template), this means that any web page can invoke the methods exposed by the ScriptHelper ActiveX control,” Will Dormann says in a blog post.
AVG confirmed the vulnerability, and stressed that it only affects Internet Explorer users. The company addressed the issue in version 18.1.7 of its AVG Secure Search Toolbar, which was released in late May as an update for existing users, and in the latest version (18.1.8) that was made available to new users on June 1.
For more information about the vulnerability, you can visit the Carnegie Mellon University CERT team website

