Running any of these security suites? You could be in serious trouble

Virus

A good number of internet security suites carry worrying flaws that could leave users open to exploit, according to some new research.

Cybersecurity firm enSilo found no less than six common problems which affect over 15 different AV products, all of which derive from the errant implementation of code hooking (used to monitor operating system functions) and injections techniques.

Microsoft's Detours, the most widely used hooking engine, is affected.

Attackers can use these flaws to get around Windows (or other apps) mitigations against exploits, and the affected security suites include many of the major players such as AVG, Avast, Bitdefender, Kaspersky, McAfee, Symantec, Emsisoft and Webroot among others.

All of these antivirus makers have been informed, and some have moved to fix the issue in the last month, enSilo noted – without specifying any names. The bad news is that patching this one up involves recompiling the product in question, so it's far from a trivial fix.

Millions affected

It's not just security suites which are hit by this, either, as the Detours hooking engine is used by many software makers, so this flaw could affect a large amount of other programs and potentially millions of users.

In a blog post, enSilo observed: "Most of these vulnerabilities allow an attacker to easily bypass the operating system and third-party exploit mitigations. This means an attacker may be able to easily leverage and exploit these vulnerabilities that would otherwise be very difficult, or even impossible, to weaponise.

"The worst vulnerabilities would allow the attacker to stay undetected on the victim's machine or to inject code into any process in the system."

The good news, such as it is, is that Microsoft has a patch to address this inbound for Detours next month. And hopefully security firms are on the ball with their own fixes – it might be a good idea to get in touch with your provider to check up on whether these issues have been addressed.

Update: We've heard from Webroot, with Eric Klonowski, Senior Advanced Threat Research Analyst, telling us: "Webroot has fully patched this vulnerability. enSilo contacted us about this vulnerability during the last week of December, and our team corrected it the following week. As security is our top priority, all Webroot customers received this update from the cloud immediately after release."

Via: PC World

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Security
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
Trojan
WhatsApp patches security flaw which let hackers install spyware
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Latest in News
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Friday, March 21 (game #383)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Friday, March 21 (game #649)
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Boston Dynamics all electric Altas
This robot can do a cartwheel better than me and now I'm freaking out – but in a good way
A image of Saros character Arjun
Housemarque’s boss is surprisingly positive about Sony’s acquisition – and it’s good news for Saros
Oura Ring 4
One of Apple's top health execs is ditching the company for Oura, and I've never been more convinced smart rings are the future