Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Trend Micro AV gave any website command-line access to Windows PCs


Recommended Posts

Posted

If you use Trend Micro anti-virus on your home PC(s) you may want to seriously consider uninstalling it and using something else. Based on the flaws found, it appears they do not have a clue about security.

 

Source: Google Security Research (via The Register, Ars Technica)

 

PCs running Trend Micro's Antivirus on Windows can be hijacked, infected with malware, or wiped clean by any website, thanks to a vulnerability in the security software.

 

The design blunders were discovered by Google Project Zero bod Tavis Ormandy. A patch is now available to address the remote-code execution flaw, so Trend Micro users should update their software as soon as possible.

 

Ormandy, who has been auditing widely used security packages, analyzed a component in Trend's AV software dubbed the Password Manager. He found that multiple HTTP RPC ports for handling API requests were accessible.

 

"It took about 30 seconds to spot one that permits arbitrary command execution, openUrlInDefaultBrowser, which eventually maps to ShellExecute()," he wrote in a bug report to Trend.

 

This means that any webpage visited by a victim could run a script that uses Trend Micro's AV to run commands directly on the machine – such as RD C:\ /S /Q to wipe the system drive, or commands to download and install malware. As another example, this code uninstalls Trend Micro's security software on a PC without the owner's knowledge or consent.

 

Then, as Ormandy looked deeper into Trend's code, more problems were discovered.

 

Because the password manager was so badly written, Ormandy found that a malicious script could not only execute code remotely, it could also steal all passwords stored in the browser using the flaws in Trend's software – even if they are encrypted.

 

Ormandy reported the flaws to Trend Micro last week, and as per Project Zero's policy, the software maker had 90 days to fix the issues before details of the bugs would be revealed in public. A new version of the antivirus has been released to address the remote-code execution hole, so information on the flaw is now available to all.

 

"Trend Micro sent me a build to verify they had fixed the problem, it looks like they're no longer using ShellExecute, so it fixes the immediate problem of trivial command execution," Ormandy said.

 

"I'm still concerned that this component exposes nearly 70 APIs to the internet, most of which sound pretty scary. I tell them I'm not going to go through them, but that they need to hire a professional security consultant to audit it urgently."

 

A spokesperson for Trend Micro told us the vulnerabilities lie in its consumer antivirus product, adding: "Tavis brought us a report of a possible vulnerability in a Trend Micro product. As part of our standard vulnerability response process we worked with him to identify and address the vulnerability. Customers are now getting protections through automatic updates."

 

Antivirus provider Trend Micro has released an emergency product update that fixes critical defects that allow attackers to execute malicious code and to view contents of a password manager built in to the malware protection program. The release came after a Google security researcher publicly castigated a TrendMicro official for the threat.

 

Details of the flaws became public last week after Tavis Ormandy, a researcher with Google's Project Zero vulnerability research team, published a scathing critique disclosing the shortcomings. While the code execution vulnerabilities were contained in the password manager included with the antivirus package, they could be maliciously exploited even if end users never make use of the password feature. Those who did use it were also susceptible to hacks that allowed attackers to view hashed passwords and the plaintext Internet domains they belonged to.

 

"I don't even know what to say—how could you enable this thing *by default* on all your customer machines without getting an audit from a competent security consultant?" Ormandy wrote in an exchange with a TrendMicro official. "You need to come up with a plan for fixing this right now. Frankly, it also looks like you're exposing all the stored passwords to the internet, but let's worry about that screw up after you get the remote code execution under control."

 

Elsewhere in the exchange, Ormandy criticized company developers for failing to move faster to contain the threat and renewed his call for them to seek help from outside security professionals. He wrote:

 

So this means, anyone on the internet can steal all of your passwords completely silently, as well as execute arbitrary code with zero user interaction. I really hope the gravity of this is clear to you, because I'm astonished about this.

 

In my opinion, you should temporarily disable this feature for users and apologise for the temporary disruption, then hire an external consultancy to audit the code. In my experience dealing with security vendors, users are quite forgiving of mistakes if vendors act quickly to protect them once informed of a problem, I think the worst thing you can do is leave users exposed while you clean this thing up. The choice is yours, of course.

Ormandy said it took him only about 30 seconds to find one of many code-execution holes in the antivirus program. In the past few days, TrendMicro began testing an emergency fix it planned to push out to end users. Ormandy said the update resolves the issue but that he remained concerned that the password manager continues to expose more than 70 potentially dangerous programming interfaces to the open Internet. In the past few years, Ormandy has exposed critical vulnerabilities in a host of security products, including those from Sophos, Kaspersky Lab, AVG and FireEye.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...