1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

A critical flaw in Symantec antivirus engine puts computers at risk of easy hacking

Discussion in 'CSO' started by RSS, May 17, 2016.

  1. RSS

    RSS New Member Member

    The antivirus engine used in multiple Symantec products has an easy-to-exploit vulnerability that could allow hackers to easily compromise computers.

    The flaw was fixed by Symantec in Anti-Virus Engine (AVE) version 20151.1.1.4, released Monday via LiveUpdate. The flaw consists of a buffer overflow condition that could be triggered when parsing executable files with malformed headers.

    According to Google security engineer Tavis Ormandy, who found the flaw, the vulnerability can be exploited remotely to execute malicious code on computers. All it takes is for the attacker to send an email with the exploit file as attachment or to convince the user to visit a malicious link.

    To read this article in full or to leave a comment, please click here

    Continue reading...
     

Share This Page