Almost every major anti-malware product has some kind of security flaw

(Image credit: Shutterstock / binarydesign)

Many anti-malware products from every major antivirus vendor feature a significant security flaw, new research has claimed.

CyberArk tested anti-malware products from Kaspersky, McAfee, Symantec, Fortinet, Checkpoint, Trend Micro, Avira, Microsoft, Avast and F-Secure to discover that they can all be abused to increase privilege on users' systems.

This is quite ironic as anti-malware solutions are supposed to protect users but they may unintentionally assist malware in gaining more privileges on a system. According to CyberArk's new blog post, many vendors fall for the same types of bugs and anti-malware products seem to be more vulnerable to exploitation due to their high privileges.

The sheer number of bugs found within anti-malware products can be staggering but many of these bugs can be easily eliminated if the security companies that make them implement several changes.

Anti-malware bugs

The first cause of many of the bugs found in anti-malware products comes from the fact that many applications on Windows use the operating system's ProgramData directory to store data that is not tied to a specific user. Programs that store data tied to a specific user generally use the %LocalAppData% directory which is only accessible by the current logged in user.

CyberArk set out to answer two questions: what happens if a non-privileged process creates directories/files that would later be used by a privileged process and what happens if you create a directory/directory-tree before a privileged process?

To answer the first question, the firm looked at Avira's AV which has two processes that write to the same log file. CyberArk was able to easily redirect the output of the write operation to any desired file by using a symlink attack. While the firm used Avira's AV as an example, it pointed out that this privilege escalation method is not limited to this product or vendor alone. To answer the second question, CyberArk's research found that in 99 percent of cases, a privileged process won't change the DACL (Discretionary Access Control List) of an existing directory.

DLL hijacking is another way in which anti-malware products can be abused for privilege escalation. This technique involves a standard user abusing DLL loading of a privileged process and successfully injecting code into it.

To prevent privilege escalation in anti-malware products, CyberArk recommends that developers change DACLs before usage, correct impersonating, update the installation framework of their software and use LoadLibraryEX.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC