ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Trend Micro flaw puts PCs in firing line

Dawn Kawamoto CNET News.com

Published: 09 Feb 2007 09:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Trend Micro is warning of a serious security flaw in several of its products that could cause a vulnerable PC to crash or be hijacked.

The flaw in its antivirus scan engine could be used to trigger a buffer overflow using a corrupted UPX file, the software maker said in an advisory issued earlier this week. For example, an outsider could send an email with the malicious file to a computer loaded with the affected antivirus software.

As a result, the PC could suffer a "blue screen of death" or allow the attacker to remotely execute code and take control of the system, Trend Micro said.

Security companies such as Secunia have rated the flaw as "highly critical". There are no exploits for the vulnerability circulating yet, Trend Micro said.

The flaw affects all of Trend Micro's products that use its scan engine and pattern file technology, including its PC-cillin line and certain versions of Client Server Messaging Security for SMB. The at-risk software makes up a wide swath of its product line.

Experts have said that antivirus software is becoming more attractive as a target for hackers. In January, Symantec acknowledged that a known hole in its corporate antivirus tool was coming under persistent attack from worms.

Trend Micro credits iDefense Vulnerability Labs, which offers a bounty to bug hunters, for reporting the problem.

The antivirus software maker is advising customers to make sure the virus pattern file for their software is updated, either manually or via automatic updates, to pattern 4.245.00. It said that it will make enhancements to its scan engine and that it plans to apply a fix with its upcoming release of Scan Engine version 8.5.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

IMMEDIATE DESKTOP SUPPORT OPPORTUNITY WEST LONDON 25-30K

MS Administration, data Recovery and Antivirus Procedures, Telephony Systems, MS 2003 & NT, MS Active Directory 2000/2003 and MS Exchange messaging ...

.NET .NET 3.5 Developer - (WFC / WFF) - Software House - London - 50K

C# for server side applications (at least 2 years) with emphasis - SOAP and ASP.NET Web Services - An understanding of STL, COM+, DCOM, and COM+ ...

Interface Developer

To ensure the on-going effective running of the Cloverleaf enterprise interface engine (messaging management transfer system) ensuring that the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment