HomeSecurityAVG, McAfee and Kaspersky antiviruses had a common vulnerability!

AVG, McAfee and Kaspersky antiviruses had a common vulnerability!

A common security bug affected the antivirus engines of three major companies, AVG, McAfee, and Kaspersky, as discovered by security researchers at enSilo.

antivirus

The issue was first identified in March 2015 when one of enSilo's products conflicted with an AVG on a customer's workstation. After further investigation into the issue, enSilo staff uncovered a bug that was the cause of the software incompatibility.

The bug is related to the fact that AVG's antivirus creates a memory space with full RWX (read-write-execute) privileges where it usually runs. For this particular version, this memory space was not random and was often shared by other applications such as Acrobat Reader.

An attacker who knew about this predictable behavior and knew where this location was could force their malicious code to execute within that address and have the same privileges. Attackers would be able to bypass Windows' built-in security features by exploiting the antivirus itself.

The companies rolled out updates to fix the problem!

After being notified, AVG employees fixed the problem in less than 2 days.

Since the bug was dangerous, enSilo decided to create a tool to check other antiviruses and it eventually turned out that McAfee Virus Scan Enterprise version 8.8 and Kaspersky Total Security 2015 – 15.x were vulnerable to the same bug.

enSilo discreetly notified the two companies without making the problem public, and they in turn addressed it immediately!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS