enSilo: AVG, Kaspersky and McAfee with vulnerable products

enSilo: Some of the biggest names in security software can be infringed by a serious flaw that allows a hacker to use a commercial security code to penetrate computers.leak security enSilo

In March, Israeli researchers ς ασφαλείας enSilo ανακάλυψαν ένα σοβαρό ελάττωμα στη ασφαλείας AVG Internet Security 2015. Διαπίστωσαν ότι το εκχωρούσε δικαιώματα μνήμης για ανάγνωση, να εγγραφής και να εκτέλεσης (RWX) σε μια προβλέψιμη που ένας εισβολέας θα μπορούσε να χρησιμοποιήσει για να πε΄ρασει κακόβουλο κώδικα σε ένα σύστημα στόχο.

EnSilo contacted AVG and the bug was repaired in the coming days. However, the company continued the investigation into other security suites and found that McAfee VirusScan Enterprise in the 8.8 and Kaspersky Total Security 2015 versions were also vulnerable.

"We will continue to update this list when we have more information," said Tomer Bitton, enSilo VP, in a publication.

“This error is a recurring Anti-Virus coding issue. We believe that this vulnerability is also likely to appear in other popular ones , which are not related to security.”

Due to the possible widespread nature of the problem, enSilo has created a free audit tool called AVulnerabilityChecker. The tool is available in Github for anyone who wants to use it.

https://github.com/BreakingMalware/AVulnerabilityChecker

Intel, owned by McAfee, and Kaspersky have already corrected their vulnerability.

So every user of these products should download and install all the latest updates.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).