By a new antivirus vulnerability

Mar 15, 2007 13:53 GMT  ·  By

Recently, the security of our computers was continuously under fire because numerous vulnerabilities were discovered in the antivirus solutions meant to defend our systems. Today, the vulnerability mania continues with another security flaw identified in Trend Micro Antivirus, a security solution able to find and eliminate the infections from our computers. The flaw discovered in Trend Micro Antivirus can allow an attacker to conduct a denial of service attack and make the computer even more vulnerable. Usually, a successful exploitation of this type of vulnerability makes the operating system crash.

"Exploitation of this vulnerability results not only in a DOS of the Trend Micro process, but in an operating system crash. There are several different attack vectors depending on which product is being targeted. Someone targeting a home user would need to convince a user to download a file from a website or an attachment from an email message.

The user would then need to manually scan this file or save it and have the Trend Micro auto scan process scan it at some later time. If instead a mail gateway is being targeted this vulnerability can be exploited automatically by sending a malicious attachment through a gateway that uses Trend Micro to scan content," iDefense Labs sustained in a security advisory.

iDefense security company sustained the flaw was confirmed only in Trend Micro Antivirus version 14.10.1041, engine version 8.320.1003, but other versions of the products might be also vulnerable. The developer of the antivirus solution sustained the only way to avoid the exploitation of the security flaw is to update your virus pattern file to 4.335.00 or higher. If you want to download Trend Micro Antivirus, you can take it from Softpedia. Trend Micro Pattern File 4.341.00 is also published on Softpedia and available as a free download.