Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • As Crypto Competition Intensifies, How Should CoinEx Futures Stand Out? bitcoin news
  • NASA Partners With Epic Games to Create a Martian Metaverse Simulation – Metaverse Bitcoin News bitcoin news
  • Ukrainian Hacker Jailed for 4-Years in U.S. for Selling Access to Hacked Servers cyber security news
  • Bitcoin Trims Gains, Why BTC Could Start Fresh Decline bitcoin news
  • How Plugin’s Blockchain Technology Helps Industries Adapt To Climate Change bitcoin news
  • Blue Chip NFTs 101 – What’s The Secret Behind CloneX? Built For The Metaverse bitcoin news
  • Sony Announces Metaverse Push in Latest Annual Corporate Strategy Meeting – Bitcoin News bitcoin news
  • Freedom Protocol Has Become the Project With the Largest Amount of IDO in the Ecology of Binance Smart Chain – Press release Bitcoin News bitcoin news

Researchers Disclose 10-Year-Old Vulnerabilities in Avast and AVG Antivirus

Posted on May 5, 2022 By root


Avast and AVG Antivirus

Two high-severity security vulnerabilities, which went undetected for several years, have been discovered in a legitimate driver that’s part of Avast and AVG antivirus solutions.

“These vulnerabilities allow attackers to escalate privileges enabling them to disable security products, overwrite system components, corrupt the operating system, or perform malicious operations unimpeded,” SentinelOne researcher Kasif Dekel said in a report shared with The Hacker News.

Tracked as CVE-2022-26522 and CVE-2022-26523, the flaws reside in a legitimate anti-rootkit kernel driver named aswArPot.sys and are said to have been introduced in Avast version 12.1, which was released in June 2016.

Specifically, the shortcomings are rooted in a socket connection handler in the kernel driver that could lead to privilege escalation by running code in the kernel from a non-administrator user, potentially causing the operating system to crash and display a blue screen of death (BSoD) error.

Vulnerabilities in Avast and AVG Antivirus

Worryingly, the flaws could also be exploited as part of a second-stage browser attack or to perform a sandbox escape, leading to far-reaching consequences.

Following responsible disclosure on December 20, 2021, Avast addressed the issues in version 22.1 of the software released on February 8, 2022. “Rootkit driver BSoD was fixed,” the company said in its release notes.

While there is no evidence that these flaws were abused in the wild, the disclosure comes merely days after Trend Micro detailed an AvosLocker ransomware attack that leveraged another issue in the same driver to terminate antivirus solutions on the compromised system.





TheHackersNews/

cyber security news

Post navigation

Previous Post: NAFSTARS Announces a Successful Fund Raise of $1․7 Million – Press release Bitcoin News
Next Post: The Importance of Defining Secure Code

Related Posts

  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys cyber security news
  • Watch Out! Hackers Begin Exploiting Recent Zyxel Firewalls RCE Vulnerability cyber security news
  • Malware Analysis: Trickbot cyber security news
  • Researchers Develop RCE Exploit for the Latest F5 BIG-IP Vulnerability cyber security news
  • Critical TLStorm 2.0 Bugs Affect Widely-Used Aruba and Avaya Network Switches cyber security news
  • Researchers Uncover Rust Supply-Chain Attack Targeting Cloud CI Pipelines cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Sequel to Iconic RPG Ni No Kuni to Feature NFT Integration and Play-to-Earn Mechanics – News Bitcoin News
  • India’s Central Bank RBI to Adopt a ‘Graded Approach’ to Digital Currency Launch – Regulation Bitcoin News
  • Ethereum Slips, What Are The Next Vital Trading Levels For The Coin?
  • We’re Approaching a Recession but It’s ‘Actually a Good Thing’ – Economics Bitcoin News
  • FTX CEO Says Crypto Exchange Is Ready to Spend Billions on Acquisition Deals – Bitcoin News

Recent Comments

No comments to show.
  • Bank of England’s Cunliffe Warns Crypto Will See Tough Times as Federal Reserve Tightens Financial Conditions – Regulation Bitcoin News bitcoin news
  • Bitcoin Selling Pressure Continues As Long-Term Holder SOPR Spikes Up bitcoin news
  • El Salvador’s Bitcoin Volcano Bonds Launch Still on Hold, According to Treasury Minister – Bitcoin News bitcoin news
  • Yes, Containers Are Terrific, But Watch the Security Risks cyber security news
  • The Best Opportunities For Traders And Passive Investors bitcoin news
  • Multi Protocol Decentralized Exchange Bashoswap Is Set to Launch It’s DEX on Cardano bitcoin news
  • As BTC Slides Toward Resistance, the Chance of a Rare Triple Top Formation Comes Into Play – Markets and Prices Bitcoin News bitcoin news
  • Ukrainian CERT Warns Citizens of a New Wave of Attacks Distributing Jester Malware cyber security news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme