Should we be surprised at this?: Company: Hackers can crack top antivirus program
Credit - CNN who credits the AP who credits eEye - I can't get no credit or satisfaction :p :
Quote:
WASHINGTON (AP) -- Symantec Corp.'s leading antivirus software, which protects some of the world's largest corporations and U.S. government agencies, suffers from a flaw that lets hackers seize control of computers to steal sensitive data, delete files or implant malicious programs, researchers said Thursday.
Link: http://www.cnn.com/2006/TECH/interne....ap/index.html
From eEye:
Quote:
Date Reported:
May 24, 2006
Vendor:
Symantec
Description:
A remotely exploitable vulnerability exists within the Symantec Antivirus program. This flaw does not require any end user interaction for exploitation and can compromise affected systems, allowing for the execution of malicious code with SYSTEM level access.
Severity:
High (Remote Code Execution)
Remote Code Execution:
Yes
Software Affected:
Symantec Antivirus 10.x
(Other Symantec AntiVirus products are also potentially affected, waiting for vendor list)
Status:
Initial report stage
Source: http://www.eeye.com/html/research/up.../20060524.html
For those with Symantec, and this is a "just-in-case" thing, what would work to replace Symantec on an enterprise level - say 30-50,000 workstations and > 5,000 MS servers? "Buelller?, Bueller?, Bueller?"
UPDATE: Symantec Updates it Advisories, cats and dogs contemplate marriage...
just in the small chance you have not seen this yet... it's wake-up time!
Updates
Symantec : http://www.symantec.com/avcenter/sec...006.05.25.html
Quote:
SYM06-010
May 25, 2006
Symantec Client Security and Symantec AntiVirus Elevation of Privilege
Revision History
May 26, 2006 - Updated Products Affected section and other details
May 27, 2006 - Updated Products Affected section with update info
- Updated Unaffected Products section
May 30, 2006 - Added CVE identifier
- Updated Products Affected section with update information
Impact
High
Remote Yes
Local Yes
Authentication Required No
Exploit publicly available No
Overview
A stack overflow in Symantec Client Security and Symantec AntiVirus Corporate Edition could potentially allow a remote or local attacker to execute code on the affected machine.
Symantec also has a page to assist with the patching: http://service1.symantec.com/SUPPORT...06052609181248
ISC : http://isc.sans.org/diary.php?storyid=13 68
and another from ISC: http://isc.sans.org/diary.php?storyid=1372
enjoy!