New security flaw in Panda Antivirus

Aug 9, 2007 10:24 GMT  ·  By

Panda Antivirus was described as a new competitor for the security giants such as Kaspersky and Symantec but it failed to reach its goal and steal an important amount of users from the rivals. Moreover, it was proved that Panda Antivirus is somehow more vulnerable than secure so it could harm your computer even without you to know. Today, a new security flaw was discovered in Panda Antivirus 2007 and 2008 that can allow an attacker to obtain higher privileges and obviously, conduct more dangerous exploits over a vulnerable system.

Security company Secunia rated the flaw as less critical but mentioned that other versions of the antivirus product might be also affected by the vulnerability.

"The problem is caused due to the application setting insecure default permissions on the "Panda Antivirus 2007" directory. This can be exploited to gain escalated privileges by e.g. replacing files in the directory. The security issue is confirmed in Panda Antivirus 2007 and has also been reported in Panda Antivirus 2008. Other versions may also be affected," Secunia mentioned in the advisory.

The only solution? "Set secure permissions on the directory," Secunia explains. Until the parent company rolls out a special patch to fix the vulnerability, you are encouraged to use this manual solution in order to avoid successful exploitation of the security flaw.

At this time, there are numerous antivirus solutions available out there but only some of them managed to convince us that they are able to protect our computers. However, many of them were affected by more or less critical vulnerabilities and even the security giants, including Kaspersky and Norton Antivirus, were involved into the notifications. For example, Symantec's Norton Antivirus wrongly flagged some Windows files as dangerous and harmed users' computers.

As usual, you can download the latest version of Panda Antivirus 2008 straight from Softpedia.