Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Kaspersky, McAfee, and AVG all vulnerable to major flaw (Update to the latest now!)
The Register ^ | Iain Thomson | Dec 10, 2015

Posted on 12/09/2015 8:09:52 PM PST by dayglored

Some of the biggest names in the security software business have been compromised by a serious flaw that could allow a hacker to use the commercial security code to infiltrate computers.

In March, researchers at security firm enSilo found a serious flaw in popular free antivirus engine AVG Internet Security 2015. They found that the software was allocating memory for read, write, and execute (RWX) permissions in a predictable address that an attacker could use to inject code into a target system.

enSilo got in touch with AVG and the flaw was fixed within a couple of days. But the team then went through other security suites and found that McAfee VirusScan Enterprise version 8.8 and Kaspersky Total Security 2015 were also vulnerable.

"We'll continue updating this list as we receive more information," said Tomer Bitton, VP of research at enSilo, in a blog post.

"Given that this is a repetitive coding issue amongst Anti-Virus - an intrusive product, we believe that this vulnerability is also likely to appear in other intrusive products, non-security related, such as application-performing products."

This isn't a theoretical attack vector. Google's in-house hacker Tavis Ormandy found a similar issue with Kaspersky and wrote a blog post detailing how to exploit the problem.

Given the possible widespread nature of the problem, enSilo has created a free checking utility called AVulnerabilityChecker and stuck it on Github for anyone to use. Intel, owner of McAfee, and Kaspersky have now fixed the issue, but users are advised to check that they have all the latest updates.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: antivirus; avg; kaspersky; mcafee; windows; windowspinglist
Navigation: use the links below to view more comments.
first 1-2021-28 next last
Make sure you get the latest updates from your AntiVirus vendor today!
1 posted on 12/09/2015 8:09:52 PM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: dayglored; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Uh-oh! Better update your anti-virus ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 12/09/2015 8:10:40 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Free NSA back door in specially marked boxes!


3 posted on 12/09/2015 8:11:33 PM PST by SpaceBar
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Eset not mentioned and its faster too.


4 posted on 12/09/2015 8:13:14 PM PST by GraceG (Protect the Border from Illegal Aliens, Don't Protect Illegal Alien Boarders...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

But but what about PC Matic that’s made Here in the USA?


5 posted on 12/09/2015 8:26:34 PM PST by bigbob ("Victorious warriors win first and then go to war" Sun Tzu.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Is AVG same as Avast?


6 posted on 12/09/2015 8:31:16 PM PST by Migraine (Diversity is great -- until it happens to YOU.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Migraine
Is AVG same as Avast?

No.

7 posted on 12/09/2015 8:34:44 PM PST by TChad
[ Post Reply | Private Reply | To 6 | View Replies]

bkmk


8 posted on 12/09/2015 8:44:18 PM PST by SaveFerris (Be a blessing to a stranger today for some have entertained angels unaware)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

We have PCMatic and we like it a lot.

The only problem is that I miss the cute blondes who used to advertise it.


9 posted on 12/09/2015 8:44:41 PM PST by TBP (Obama lies, Granny dies.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thanks for the ping. I’m gonna check my Kaspersky, but it should be up to date. I have Kaspersky Internet Security 2015, not Kaspersky Total Security 2015, but I’m gonna check anyway.


10 posted on 12/09/2015 8:58:32 PM PST by matthew fuller (GWB Legacy: BHO, US Jihadi in Chief. BHO Legacy: ISIS.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Hmmmmm ..?? I have not had any issues with Norton !! My system is working just fine.


11 posted on 12/09/2015 9:33:21 PM PST by CyberAnt ("The fields are white unto Harvest")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ..
Kaspersky, McAfee, and AVG all vulnerable to major flaw (Update to the latest now!) All Apple Boot Camp and VM users running Windows who have selected to run one of these anti-virus applications should immediately update it! -- PING!

Thanks to dayglored for posting and pinging.


Apple Virtual Windows users' Security Alert!
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

12 posted on 12/09/2015 9:33:26 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: matthew fuller
I’m gonna check my Kaspersky, but it should be up to date. I have Kaspersky Internet Security 2015, not Kaspersky Total Security 2015, but I’m gonna check anyway.

Me, too. I have KIS 2015 also.

13 posted on 12/09/2015 10:06:37 PM PST by EinNYC
[ Post Reply | Private Reply | To 10 | View Replies]

To: dayglored

Hackers are not invading personal computers. The money is invading-hacking corporate computer systems. Small businesses.


14 posted on 12/09/2015 10:07:15 PM PST by dennisw (The first principle is to find out who you are then you can achieve anything -- Buddhist monk)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I have McAfee on the work boxes. It doesn’t catch anything. Symantec sort of did once in a while.


15 posted on 12/10/2015 3:57:26 AM PST by wally_bert (I didn't get where I am today by selling ice cream tasting of bookends, pumice stone & West Germany)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
what do you think of Ad-Aware?
16 posted on 12/10/2015 4:34:51 AM PST by Chode (Stand UP and Be Counted, or line up and be numbered - *DTOM* -w- NO Pity for the LAZY - Luke, 22:36)
[ Post Reply | Private Reply | To 1 | View Replies]

To: The Final Harvest

I’ve had Norton on this computer since Day One (I’ve had it four years). Yesterday it seemed a little wonky so I ran Malwarebytes, and dang, if I hadn’t picked up PUP.Optimal.InstallCore.

Thanks to Malwarebytes directions, and two other cleaning programs later, I got all the damage off, but I am not a happy camper! I don’t download programs and thought I was careful when surfing but evidently not.


17 posted on 12/10/2015 4:50:02 AM PST by LSAggie
[ Post Reply | Private Reply | To 11 | View Replies]

To: dayglored

Used to go with AVG but switched to Windows Defender a few years ago and haven’t had an issue. I practice safe browsing and use the Avira Browser Safety plug-in with Chrome. My wife uses FireFox with the AVG Site Safety plugin.


18 posted on 12/10/2015 5:21:09 AM PST by trebb (Where in the the hell has my country gone?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: trebb

Avira user here...and disconnected Defender - too many reports of so-so performance. Avira is relatively “light weight”, too.


19 posted on 12/10/2015 5:24:26 AM PST by newfreep (TRUMP/Cruz 2016 - "Evil succeeds when good men do nothing" - Edmund Burke)
[ Post Reply | Private Reply | To 18 | View Replies]

To: dayglored

If you’re using Windows, I highly recommend you use Windows Defender with the firewall or MS Security Essentials. They are designed to work in tandem with the OS, are a much smaller footprint than third-party AV, and they are updated regularly by MS updates.


20 posted on 12/10/2015 5:54:07 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-28 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson