One of Google 's security experts discovered an exploit for a zero-day vulnerability in Avast antivirus that had even been recently patched.
The researcher is Tavis Ormandy , one of Google 's Project Zero engineers , the same person who discovered a similar zero-day exploit in Kaspersky antivirus exactly a month ago.
According to Ormandy, the bug manifests itself when users access websites protected via HTTPS connections.
Avast was performing a "legitimate" MitM for SSL connections .
Avast antivirus trafficto scan for threats, but by using a flawed method for parsing X.509 certificates, this would allow attackers to execute code on the user's computer.
The only requirement was that users had access to a malicious website, which isn't that far-fetched of a scenario. The researcher released a proof-of-concept to Project Zero after the famous antivirus company fixed the issue.
This is the third antivirus solution we've seen with a zero-day in just one month.
Earlier, there was a report about Kaspersky, which included a zero-day bug that allowed hackers to easily penetrate the victim's computer, and gain system-level privileges, allowing them to carry out all kinds of attacks without restrictions.
This was followed by the one at FireEye , which allowed unauthorized remote access with administrator privileges. None of these had been exploited “in the wild” as appears to have been the case with the Avast bug .
