Avast antivirus hole patched after public Project Zero slap

Status
Not open for further replies.
L

LabZero

Thread author
Google Project Zero hacker Tavis Ormandy has found a since-patched vulnerability in Avast antivirus that allows attackers to gain remote code execution privileges.

Ormandy says the man-in-the-middle diddle Avast uses to conduct encrypted traffic analysis as it hits browsers is insecure, thanks to bad X.509 certificate parsing.

It appears Avast users would need to follow a link generated by attackers and possibly ignore any code execution warnings order to be p0wned.

"If you're gonna MITM Chrome's SSL at least get an intern to skim your X.509 parsing before shipping it," Ormandy says.

The hacker noted the vendor's seven day patch turn around time but chided one Avast security bod, saying in a tweet that the vendor is lucky attackers have not built worms targeting its products.

Ormandy released proof of concept information on the Google Project Zero asset.

Avast has not yet updated its site detailing the patch release notes. ®
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top