February 25, 2005

Trendmicro security flawed


by brian_turner

Trendmicro has become the third security vendor to be warned by Internet Security Systems that its code could execute malicious programs, rather than remove them.

As reported in Take three: Antivirus apps could spread infection, this follows on earlier discoveries that Symantec and F-Secure software was also vulernable to the same issue, as reported here in Security companies patch serious flaws.

According to CNET:

The vulnerability affects Trend Micro’s Antivirus Library, a common set of code used by at least 29 Trend Micro products, according to separate advisories posted on Trend Micro’s Web site on Wednesday and on ISS’ site on Thursday. An attacker could create a program that exploits the security hole, causing the antivirus program to run a virus instead of blocking the malicious program, the companies said.

“Successful exploitation of this vulnerability could be used to gain unauthorized access to networks and machines being protected by Trend Micro Antivirus Library products,” ISS said in its advisory.

Trendmicro have now released an advisory for the update of it’s products here: Vulnerability in VSAPI ARJ parsing could allow Remote Code execution.

Questions? Discuss this in our Internet Business forums for help and advice

Story link: Trendmicro security flawed

Add to Bookmarks:

ADD TO DEL.ICIO.US     ADD TO DIGG     ADD TO FURL
ADD TO STUMBLEUPON     ADD TO YAHOO MYWEB     ADD TO GOOGLE     ADD TO SPURL

 

Leave a Reply




 

Previous: « IBM powers PHP
Next: Google AdSense problems »

Visited 2380 times, 4 so far today