Zero-Day Exploit Found in Avast Antivirus

Status
Not open for further replies.

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
One of Google's security experts found a zero-day exploit inside the Avast antivirus, which the company has recently patched.
The researcher is Tavis Ormandy, one of Google's Project Zero engineers, the same man that discovered a similar zero-day exploit in Kaspersky's antivirus exactly a month ago.
According to Ormandy's research, the bug manifested itself when users would access Web pages protected through HTTPS connections.
Avast was performing a "legal" MitM for SSL connections

Because the Avast antivirus would tap into encrypted traffic so it could scan for threats but was using a faulty method for parsing X.509 certificates, this would have allowed attackers (if aware of the issue) to execute code on the users' computer.
The only condition was that users would access a malicious HTTPS website, which is not such a far-fetched scenario.
Ormandy released a proof-of-concept on Project Zero's Google Group after the antivirus company issued a fix.

Full article. Zero-Day Exploit Found in Avast Antivirus
 

bayasdev

Level 19
Verified
Top Poster
Well-known
Sep 10, 2015
901
Avast replaces SSL certificates for their own certificates for analyze SSL pages, nothing is perfect
 

DoxThis

Level 3
Verified
Apr 25, 2015
135
The problem with alot of av's nowadays is most can be exploited due to the various issues in how files are opened such as .tar's and .zip's which isn't really their fault after all they didn't make those file formats. Most have fixed these exploits but not completely
 
  • Like
Reactions: XhenEd
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top