Home TrendMicro hole gives attackers the keys to affected PCs
News

TrendMicro hole gives attackers the keys to affected PCs

Bruno Ferreira
Disclosure
Disclosure
In our content, we occasionally include affiliate links. Should you click on these links, we may earn a commission, though this incurs no additional cost to you. Your use of this website signifies your acceptance of our terms and conditions as well as our privacy policy.

The Tech Report Why Trust Tech Report Arrow down

Tech Report is one of the oldest hardware, news, and tech review sites on the internet. We write helpful technology guides, unbiased product reviews, and report on the latest tech and crypto news. We maintain editorial independence and consider content quality and factual accuracy to be non-negotiable.

A recent version of TrendMicro Antivirus contained a serious security vulnerability that would let a remote attacker run arbitrary commands on the target system and steal users' passwords. The now-patched flaw was present in the software's password management component and was discovered by security researcher Tavis Ormandy of Google Project Zero.

After installing TrendMicro Antivirus, Ormandy noticed that the software was listening on a few network ports for no apparent reason. After some investigation, he discovered that the password management component fires up a web server which exposes utility APIs to the internet. According to Ormandy, it took him "about 30 seconds to spot one that permits arbitrary command execution."

The researcher provided a proof-of-concept page that would uninstall the TrendMicro software from a test system. He noted that an attacker could silently exploit the bug, as TrendMicro adds its own self-signed certificate to the system, meaning a victim wouldn't see any security alerts. Adding insult to TrendMicro's injury, he then found out that additional vulnerabilities in the way the password manager handled management commands originating from TrendMicro's servers. These vulnerabilities could let an attacker steal the user's stored passwords, even if they were encrypted.

TrendMicro has since patched its software to ensure that any remote requests to the password manager come from the company's own servers. Details on the bug have since then been made public, as part of Project Zero's responsible disclosure policy.

The Tech Report - Editorial ProcessOur Editorial Process

The Tech Report editorial policy is centered on providing helpful, accurate content that offers real value to our readers. We only work with experienced writers who have specific knowledge in the topics they cover, including latest developments in technology, online privacy, cryptocurrencies, software, and more. Our editorial policy ensures that each topic is researched and curated by our in-house editors. We maintain rigorous journalistic standards, and every article is 100% written by real authors.

Latest News

How to lie with statistics
Science Statistics

How to Lie with Statistics – Misleading Ways to Use Numbers

Pepe Bullish Trend Continues – Pepe Unchained Breaks $4M Barrier
Crypto News

Pepe Bullish Trend Continues – Pepe Unchained Breaks $4M Barrier

Pepe-themed coins have exploded in the last week, with Pepe increasing by 28.36% and Pepe Coin by 30.14%. PepePAD is also up by 28.89%, showing good upside potential. One Pepe-themed...

Researchers Shed Light on DarkGate Malware That Targeted Users from North America, Europe, and Asia
News

Researchers Shed Light on DarkGate Malware That Targeted Users from North America, Europe, and Asia

A short-lived malware campaign, which distributed the DarkGate malware-as-a-service payload through the exploitation of Samba file shares, had hit Europe, North America, and certain parts of Asia between March and...

Elon Musk to Move X and SpaceX Headquarters from California to Texas
News

Elon Musk to Move X and SpaceX Headquarters from California to Texas

Anthropic and Menlo Ventures to Launch a $100M Startup Fund
News

AI Startup Anthropic and Menlo Ventures Join Hands to Launch a $100 Million Startup Fund

Amazon Prime Days Lead to More Injuries among Workers
News

Amazon Prime Days Lead to More Injuries Among Workers: Senate Probe Reveals

BlackRock's IBIT Records Massive Inflow of $260 Million as Bitcoin ETFs Record Eighth Day of Inflows
News

BlackRock’s IBIT Records Massive Inflow of $260 Million as Bitcoin ETFs Record Eighth Day of Inflows