Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Symantec Confirms Serious AV Security Flaw

Add as a preferred source on Google

Symantec Corporation has publicly acknowledged a serious security vulnerability in its AntiVirus Library which could lead to execution of arbitrary code when scanning RAR archive files. The issue impacts a dozens of Symantec’s enterprise and consumer products for Windows, as well as recent antivirus products for Macintosh, Linux, Solaris, AIX and handheld devices.

Symantec rates the vulnerability as “high” risk, and says it is “currently working to create and distribute product updates for all affected products.”

Recommended Videos

Symantec’s statement comes a day after security researcher Alex Wheeler published an public advisory about the problem (PDF).

The issue involves multiple unchecked 16-bit fields in RAR archive sub-block header types. In theory, an attacker could craft an RAR archive to overwrite critical areas of memory with arbitrary data; when executed, this code could execute an attack granting system-wide privileges to the affected system. Since Symantec’s antivirus products scan files coming in via email and other means automatically, the user would not have to view an email message or open an attachment to trigger the attack: it would happen automatically.

To date, there are no known exploits of this bug. As an interim measure, users could consider disabling scans of RAR compressed files and RAR self-extracting archives.

The RAR compression format is relatively popular, particularly among users compressing large audio or video files. As a result, virus creators have increasingly begun bundling malware into RAR archive files to sneak “under the radar” of antivirus products operating on mail servers and other perimeters of networks. Antivirus products can typically scan the contents ZIP archives, but not all can yet scan inside RAR files. Symantec’s products can do so, and the security bug lies within that capability.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Deepfake bosses are crashing video calls, and researchers are trying to expose them
Seeing your boss on video no longer proves they are real
Researchers at Fraunhofer SIT are fighting against deepfake meeting video calls

Entering into a meeting with your boss and several familiar coworkers inside a video conference is the next area vulnerable to cybercrimes, and it's all because of deepfake technology. Researchers at the Fraunhofer Institute for Secure Information Technology SIT are working on a real-time warning system designed to identify attempted fraud during corporate video conferences.

The report states that criminals are increasingly targeting video meetings for identity theft and financial scams, taking advantage of the trust people place in familiar faces and voices. The intention is to flag suspicious activity while the meeting is still taking place. This gives an employee a chance to stop before following an expensive instruction from an AI-generated executive.

Read more
Apple will finally stop making iPhone-to-Windows copy-paste such a chore
Your iPhone may finally copy and paste with a Windows PC like it should
Apple Universal Clipboard feature

Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.

Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.

Read more
Chrome wants more extension reviews, but good ratings won’t keep malware out
Google is testing built-in extension review prompts, but good ratings can still hide malware
malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more