Email us! Subscribe to Liquidmatrix!

Path-conversion Weakness In Major AV Products Reported

OK, so what do Norton AV, Kaspersky AV, AVG AV, Norman AV, Ad-Aware, Spybot Search&Destroy and all Windows versions from NT4.0SP1 to Windows Server 2003 SP1 all have in common? A rather nasty design flaw apparently.

Reportedly “there is a design flaw in the way that NTDLL performs path conversion between DOS style path names and NT syle path names. Although many attack vectors are possible, in this paper [see later] some proof of concept cases are covered”. “This issue occurs because the operating system uses multiple differing algorithms to resolve file paths. Attackers may exploit this issue to bypass security software such as antivirus and antispyware products. Other attacks may also be possible.”, continues Symantec.

The folk at SANS ISC have verified the aforementioned behaviour. Make sure your antivirus signatures are up to date.

Article Link

Tags: , , , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • I’m Getting Annoyed With A Vendor
  • Microsoft Releases File Block Functionality For Office
  • Cisco Products SSL/TLS and SSH Validation Security Issue
  • Mac OS X Application Firewall Weaknesses
  • SSL-Explorer Multiple Vulnerabilities
  • Leave a Comment