Symlink Race Bugs Found in 28 Antivirus Products

Symlink Race Bugs Found in 28 Antivirus Products


Security researchers at RACK911 Labs said in a recent report that they found "symlink race" vulnerabilities in 28 of today's most popular antiviruses. According to RACK911, the flaws can be exploited by an attacker to delete files used by the antivirus or by the operating system, resulting in crashes or rendering the computer unusable.

The vulnerability at the heart of these bugs is called the " symlink race " explains ZDNet Dr. Vesselin Bontchev,  member of the National Laboratory of Virology of the Bulgarian Academy of Sciences. A symbolic link vulnerability occurs when you link a malicious file and a legitimate file together, and end up performing malicious actions on the legitimate file. Symlink race vulnerabilities are often used to link malicious files to higher privilege items, resulting in the elevation of privilege attacks.

“This is a very real and ancient problem with operating systems that allow concurrent processes,” Dr. Bontchev told ZDNet. “We found that many programs suffered from this in the past. "

Research Started in 2018

In a report released last week, the RACK911 team said it has been investigating the presence of these flaws in antivirus products since 2018. They found that 28 products on Linux, Mac and Windows were vulnerable and notified vendors gradually. “Most antivirus vendors have fixed their products, with a few exceptions,” the RACK911 team said. Some publishers have acknowledged the problems in public notices [ 1, 2, 3, 4 ], while others appear to have implemented silent fixes. The RACK911 team did not name the products that were not patched.

RACK911 claims that antivirus products, in particular, are vulnerable to this type of attack, because of the way they work. There is a gap between when files are scanned and found to be malicious and when the antivirus steps in to remove the threat. The attack relies on replacing the malicious file with a symbolic link to a legitimate file within this period of time.

RACK911 researchers have created proof-of-concept scripts that abuse a run condition (symbolic link) to link malicious files to legitimate files via directory junctions (on Windows) and symbolic links (on Mac and Linux). When the antivirus detects the malicious file and decides to delete it, it ends up deleting its own files or deleting the main files belonging to the operating system.

“In our testing on Windows, macOS, and Linux, we were able to easily remove important files related to anti-virus software that made it ineffective and even remove key operating system files that would cause significant corruption requiring a complete system reinstallation. operating, ”said the RACK911 researchers.

Most of the bugs have been fixed

The RACK911 proof of concept code released last week only deletes files. According to Dr Bontchev, such attacks would be more dangerous if they rewrote the files, which might be doable, and would lead to a complete takeover of the attacked system.

Real-world attacks using the bugs in RACK911 would require an attacker to be able to download and then execute the symbolic link attack code on a device. It is not something that can help attackers hack into a system, but something that could help them improve their access to a hacked system.

This means that this type of bug can only be used as a second stage payload in a malware infection, to elevate privileges, to disable security products, or to sabotage computers in a destructive attack. “Make no mistake, exploiting these vulnerabilities was pretty trivial, and seasoned malware writers will have no problem arming the tactics outlined in this blog post,” the RACK911 team said.

So far, the majority of bugs that RACK911 has found in antivirus products have been fixed. However, variations could be easily discovered. Symlink racing condition bugs have been among the oldest and most difficult to mitigate in applications over the past decades, across all operating systems.

Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software