Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Researcher finds gaping holes in Trend Micro antivirus
iTnews aus ^ | Jan 13 2016 6:40AM (AUS) | Juha Saarinen

Posted on 01/12/2016 6:43:44 PM PST by Utilizer

A Google Project Zero researcher has left security vendor Trend Micro with egg on its face, after discovering its software contains multiple, serious vulnerabilities that are easy to exploit without user interaction or notification.

Tavis Ormandy of Project Zero noted that when Trend Micro antivirus is installed on Windows, the password manager component - written mostly in Javascript using the node.js framework that's included by default - allows any any website to run arbitrary code on users' machines.

The flaw in password manager allegedly took Ormandy only about 30 seconds to discover.

He said the vulnerability is trivial to exploit, and can be used to execute commands without any visible prompts or notifications to users, who would be unaware that their machines are being attacked.

Ormandy reported the issue to Trend Micro, which has developed a fix for the problem.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: malware; microsoft; security; windows
Not a complete fix...
1 posted on 01/12/2016 6:43:44 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

Trend Micro has always been a POS.


2 posted on 01/12/2016 6:45:51 PM PST by ButThreeLeftsDo (Get Ready)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

“But the salesman said that the Indian programmers were just as good as anyone we could hire in Australia....”


3 posted on 01/12/2016 6:48:18 PM PST by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: ButThreeLeftsDo

Worse than PC Matic?


4 posted on 01/12/2016 6:49:10 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: proxy_user
...just as good as anyone we could hire in Australia...

*-that knows next to nothing about adware, bloatware, malware, virusware, worms, basic security functions, or also happens to speak EaaSL.

5 posted on 01/12/2016 6:53:32 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

Neck and Neck...


6 posted on 01/12/2016 6:54:34 PM PST by ButThreeLeftsDo (Get Ready)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

Over at /. they’re saying this involves a “FREE!!” password manager written in javascript, offered as an install option. That would be a bad thing and very unprofessional.


7 posted on 01/12/2016 7:09:15 PM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: ButThreeLeftsDo

I had Trend Micro once. It was crap. Got rid of it and it was addition by subtraction.


8 posted on 01/12/2016 7:15:21 PM PST by henkster (Hillary Clinton's supporters are beginning to realize they are fettered to a corpse.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: henkster

First PC came with Trend Micro.

Everything went south.

Called “customer service”.

My ear is still ringing from them hanging up on me.

(1997)


9 posted on 01/12/2016 7:27:07 PM PST by ButThreeLeftsDo (Get Ready)
[ Post Reply | Private Reply | To 8 | View Replies]

To: ButThreeLeftsDo

Oddly enough, I underwent a strikingly similar experience not long before yours, only I was asking some rather pointed questions of the INS...

Apparently, the were quite unwilling to reply with any exact answers. After determining that I was determined to get specific details on their official procedures, rules, and regulations they decided to abruptly end the phone call.

Quite abruptly.


10 posted on 01/12/2016 7:41:20 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Utilizer

Well, I see that I am not alone!


11 posted on 01/12/2016 7:45:00 PM PST by ButThreeLeftsDo (Get Ready)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer

Hrrmph!... Apparently “they” were, not apparently “the” were.

Typing too fast. :)


12 posted on 01/12/2016 7:48:27 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer; dayglored

PING for your Microsoft list members who may be using Trend Micro antivirus. . .


13 posted on 01/12/2016 8:49:03 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson