Another flaw affects swathe of CA products

By
Follow google news

Computer Associates (CA) has warned of yet another “high risk” vulnerability affecting an antivirus scanning engine used in many of its products.

The flaw lies in the company's Vet antivirus scanning engine that is used in a vast range of its enterprise and consumer products as well as other vendors that used the scanning engine in their products.


CA said the problem was a high risk as an attacker could gain control over a user's PC just by sending them a specially crafted Microsoft Office document. The user would not have to do anything for the attack to be effective.

The company was informed of the flaw by Alex Wheeler of rem0te.com. In his advisory he said that "successful exploitation of protected systems allows attackers unauthorized control of data and privileges. It also provides leverage for further network compromise."

He added that the vulnerability "could be triggered without authentication or user interaction and allows multiple exploitation attempts. Vet implementations are likely vulnerable in their default configuration."

As reported by SC Magazine in March, vulnerabilities in CA Licensing software opened up vast swathes of the CA product catalog to potential attack.

A patch is available on the company's website.

http://www.rem0te.com/public/images/vet.pdf
www.ca.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Australia's new cyber affairs ambassador sourced from ASD

Australia's new cyber affairs ambassador sourced from ASD

Hackers using F5 devices to target US gov networks

Hackers using F5 devices to target US gov networks

Microsoft breaks Windows 11 Recovery Environment in October update

Microsoft breaks Windows 11 Recovery Environment in October update

Log In

  |  Forgot your password?