eEye Digital Security, developer of network security and vulnerability management software solutions, has discovered Big Yellow, a non-Microsoft-based malware that has both worm and botnet characteristics and is currently propagating in the wild using Symantec's anti-virus software.
Big Yellow exploits a vulnerability in the remote management interface for versions of Symantec AntiVirus and Symantec Client Security, which could be remotely exploited by an anonymous attacker to execute arbitrary code with SYSTEM privileges on an affected system, giving the attacker complete control.
Many IT departments are not prepared for attacks on non-Microsoft-based applications and have not yet deployed the patch available for this widely deployed anti-virus software.
eEye discovered this vulnerability in late May 2006 and worked with Symantec to create a patch at that time. However, many IT departments have not deployed this patch.
"Given the rapid discovery of critical security vulnerabilities within desktop applications other than Microsoft, the release of malware of this magnitude targeting non-Microsoft software was only a matter of time," said Marc Maiffret, eEye's founder and CTO. "IT urgently needs to understand that the new vector for attack will not come from Microsoft, but from the myriad applications that are scattered throughout its network. From anti-virus to iTunes, these non-Microsoft desktop applications, many of which IT is not even aware of, will become the enterprise's biggest point of vulnerability very, very quickly."
eEye's research team, discovered the Big Yellow malware late on December 14 on its 'honey pot' network — a network designed specifically to identify new classes of attack.
Click here for more info.
Worm Hits Symantec's Anti-virus Software
By: Sharon Khare
| Dec 17, 2006
| Ads by Google | ||
Why don't you post one?
LATEST NEWS
- Make VoIP Calls From Your iPod Touch
- Airtel Offers Online Account Management
- Bluetooth 2.2 To Be Introduced In 09
- Sanyo Releases Wi-fi Radio
- SanDisk Launches Enterprise Cruzer USB Drive
- Mirror's Edge PC Version Dated
- GRID DLC Available Now
- Fable 2 DLC Hits Xbox Live This December
- Grand Theft Auto Invading India
- Rockstar Responds to GTA IV PC Issues
| Ads by Google | ||
RELATED
Hot Searches & Keywords :
AMD
ATI
Acer
Adobe
Apple
Asus
Benq
Blackberry
Blizzard
Blu-Ray
Bluetooth
CES 2007
Canon
Capcom
Creative
DVD
Dell
E3 2007
E3 2008
EA
Electronic Arts
Facebook
Google
HP
Halo
IBM
ITunes
Intel
Internet
Ipod
LCD
LG
Linux
Logitech
Microsoft
Mobile
Mobile Phone
Mobile Phones
Motorola
Mp3
Myspace
Nintendo
Nokia
Nvidia
PC
PMP
PS2
PS3
PSP
Philips
Reliance Communications
Samsung
Sandisk
Search Engine
Skype
Smartphone
Sony
Sony Ericsson
Toshiba
Ubisoft
Valve
Vista
Voip
Website
Wii
Windows
Windows Mobile
Windows Vista
WoW
Xbox 360
Xbox Live
Xbox360
Yahoo!
Youtube
Zune
digicam
digital camera
iPhone
laptop
mp3 player
printer
social networking site
test
yahoo
| Ads by Google | ||
|
|
Sections
Products
Camcorders |
Controllers |
CPUs |
Desktop PCs |
Digital Cameras |
Digital Video Recorders |
DVD Players |
Games |
Gaming Consoles |
General |
GPS Systems |
Handhelds / PDAs |
Hard Drives |
Headphones & Headsets |
HiFi Audio Systems |
Home Theater Systems |
Input Devices |
Internet |
Laptops |
lenovo |
Low Level Components |
Mac Systems |
Mobile Phone Accessories |
Mobile Phones |
Monitors |
Motherboards |
MP3 / Audio Players |
Multi-Function Devices |
Networking |
Optical Drives |
PC Accessories |
PC Add-on Cards |
PC Cabinets |
PC Games |
Printers |
Projectors |
RAM Modules |
Scanners |
Software |
Speakers |
Telecom |
TVs |
Video Players |


