Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Avira Free Antivirus intercepts passwords from browsers and publishes them in the con
#1
Avira Free Antivirus intercepts passwords from browsers and publishes them in the console


Engineers from Doctor Web found a dangerous vulnerability in Avira Free Antivirus. One of the main components of the protection program collects credentials from browsers

The results of the investigation were reported by the timlid and reverse engineer from the company "Doctor Web" Nikolenko Constantine (also known as Veliant). When analyzing the Avira Free Antivirus solution of the German company Avira GmbH & Co. KG has determined that one of the components collects credentials and displays them in the console.

Technical details
A vulnerability was detected while analyzing a component named "Avira.PWM. NativeMessaging .exe" located at "% ProgramFiles%\Avira\Launcher\." Its code is compiled for the .NET platform and is not obfuscated, which allows you to verify its functionality.

"Avira.PWM. NativeMessaging .exe" is a console utility that reads the user input and processes it further.

The Read function reads user input data from the Standard input (stdin) and passes it to the ProcessMessage function. If the passed command uses the fetchChromePasswords or fetchCredentials methods, the RetrievBrowserCredentials function is called.

In turn, the "RetrievBrowserCredentials" function collects the credentials saved by the user in browsers (Chrome, Firefox, Opera, Edge) and stores them as a JSON object. The collected data is then output to the terminal in a string form.

Risks of safety
The Avira.PWM. NativeMessaging .exe component causes several security issues. First, a binary file digitally signed by Avira collects user credentials. Second, the program calling the binary file is not verified in any way, that is, the call can initiate malware. Finally, the component works offline as a separate application.

A CVE-2020-12680 ID has been assigned to this vulnerability. Avira was informed of the problem on April 7, 2020, but a month later, the described component is still available in Avira 's Free Antivirus distribution. In addition, the German vendor did not respond to letters reporting vulnerability.



https://www.comss.ru/page.php?id=7430

https://habr.com/ru/post/500852/
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Avira Unveils Extended Features with Avira Crypto, Game Booster and Breach Monitor mrtrout 0 645 10-29-2021 , 01:50 AM
Last Post: mrtrout
  NortonLifeLock Buys Avira to Expand Into Freemium Antivirus Protection mrtrout 0 1,000 12-09-2020 , 01:26 AM
Last Post: mrtrout
  5 Most Secure Browsers Mike 8 4,353 12-28-2018 , 07:15 AM
Last Post: gdant
  Researcher publishes proof-of-concept code for creating Facebook worm Mohammad.Poorya 0 1,724 12-24-2018 , 05:29 PM
Last Post: Mohammad.Poorya
  Avira Free Antivirus (New Features Added) mrtrout 0 1,561 12-18-2017 , 11:44 PM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)