A critical flaw in Symantec antivirus engine puts computers at risk of easy hacking

The antivirus engine used in multiple Symantec products has an easy-to-exploit vulnerability that could allow hackers to easily compromise computers.

The flaw was fixed by Symantec in Anti-Virus Engine (AVE) version 20151.1.1.4,  released Monday via LiveUpdate. The flaw consists of a buffer overflow condition that could be triggered when parsing executable files with malformed headers.

According to Google security engineer Tavis Ormandy, who found the flaw, the vulnerability can be exploited remotely to execute malicious code on computers. All it takes is for the attacker to send an email with the exploit file as attachment or to convince the user to visit a malicious link.

To read this article in full or to leave a comment, please click here

Read more: A critical flaw in Symantec antivirus engine puts computers at risk of easy hacking

Story added 17. May 2016, content source with full text you can find at link above.