Re: Microsoft Antisypware (Beta) vulnerability

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 02/11/05


Date: Thu, 10 Feb 2005 20:49:47 -0500

I look at it from the POV of all the infectors known to shutdown AV and FireWall apps. They
weren't vulnerabilities.

If you are talking MSAV, that was Central Point AV by Central Point Software which was OEM'd
to Microsoft back in WfW days. Central Point Software was bought by Norton and subsequently
the product line was dropped and the code for CPAV was incorporated into NAV. One of the
reasons why NAV rose in quality of its catch rate.

-- 
Dave
"Bigbruva" <Richardh@dontusethis.ws> wrote in message
news:%239PQol9DFHA.3888@TK2MSFTNGP09.phx.gbl...
| That is an excellent point David.
|
| Just as the old Microsoft Antivirus* application from the days of DOS was a
| target for virus writers!
| It is difficult to see how MSAS can defend itself from this sort of attack.
| If you are logged on as an admin and are tricked into running applications
| like this you are going to get into trouble :-(
|
| BB
|
| * This was a licensed cut down version of Norton's AV tool if I remember
| correctly.
|
| "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
| news:ux9fyO9DFHA.3416@TK2MSFTNGP09.phx.gbl...
| > That's not a vulnerability.
| >
| > A vulnerability means there is a bug in the software that can be
| > exploited.  That's not the
| > case here.
| >
| > -- 
| > Dave
| >
| >
| >
| >
| > "Pam" <phfloresatverizondotnet> wrote in message
| > news:eEcvn47DFHA.328@tk2msftngp13.phx.gbl...
| > | Has anyone had the following problem reported by Sophos?
| > |
| > | "A new malware program, BankAsh-A, is already on the loose, according to
| > | security firm Sophos PLC. It tries to disable Microsoft AntiSpyware
| > | software and delete all files within that program's folder."
| > |
| > |
| > |
| > | http://www.computerworld.com/newsletter/0,4902,99666,00.html?nlid=AM_A
| > |
| > |
| > | Pam
| > |
| > |
| >
| >
|
|


Relevant Pages

  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #83
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability ... Microsoft Internet Explorer History List Script Injection ... Microsoft Windows 2000 Lanman Denial of Service Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #81
    ... MICROSOFT VULNERABILITY SUMMARY ... WWWIsis Remote Command Execution Vulnerability ... Windows NT 4.0 Print Spooler Security ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #185
    ... NEW MICROSOFT VULNERABILITIES - Audit Your Network Security ... SurgeLDAP User.CGI Directory Traversal Vulnerability ... Microsoft Windows H.323 Remote Buffer Overflow Vulnerability ... Microsoft Jet Database Engine Remote Code Execution Vulnerab... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #336
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows Unspecified Remote Code Execution Vulnerability ... Microsoft Windows Explorer BMP Image Denial of Service Vulnerability ... An attacker could leverage this issue to have arbitrary code execute with kernel level privileges. ...
    (Focus-Microsoft)