Skip to main content

New exploit uses antivirus software to help spread malware

Hacker
hamburg_berlin/Shutterstock
One of the most basic rules of safe web browsing is to use antivirus software in order to keep your computer safe. While it’s a good idea to make use of such software, but a recently discovered exploit proves that even the best antivirus software is not fool proof.

Nicknamed AVGater by Austria-based security consultant Florian Bogner, the exploit takes advantage of the “restore from quarantine” function found on many antivirus programs. The concept behind the exploit is fairly simple one. It allows a user to move a piece of malware from the quarantined folder to somewhere else on the victim’s computer, allowing the malware to be executed.

Bogner uploaded a video that provides more information on how the exploit works.

Under normal circumstances, the restore from quarantine function would not allow a non-administrator to write a file to the computer’s C:\Program Files or C:\Windows folders, but this attack takes advantage of Windows’ NTFS function to grant the user access to these folders.

As impressive as this all sounds, there is one major flaw which will drastically limit the scope of this exploit. In order to do any of this, the hacker in question must physically be at the computer they wish to infect. Given that most malware is spread via the internet, it is unlikely that this exploit will cause major problems.

Enterprise computers could be the devices most at risk to this sort of attack. While we don’t see it being a widespread problem, it’s feasible that a disgruntled employee could decide to get a little revenge, though such cases are rather limited in nature; most people won’t risk their jobs or prison for such a stunt. That being said, Bogner offered a simple fix to this problem by simply disabling the remove from quarantine feature on enterprise computers.

In terms of antivirus programs, Bogner has notified the vendors of the various software which contain this flaw and many have already rolled out patches to fix this issue.

Exploits such as this are found from time-to-time, but that shouldn’t dissuade users from installing antivirus software as it remains one of the best, though not unquestioned, ways to keep a computer safe from malware and other issues.

Eric Brackett
Former Digital Trends Contributor
I reviewed two of the best password managers. Here’s the one I recommend people use
A side-by-side comparison of 1Password and Bitwarden pricing appears on a PC monitor.

If you need more convenience, protection, and cross-platform integration than you can get with your browser’s autofill, you need a premium password manager like 1Password or Bitwarden. I recently reviewed both and put together this comparison to help you pick which works best for you.
Tiers and pricing
A side-by-side comparison of 1Password and Bitwarden pricing. Digital Trends

1Password is only available as a subscription, but Bitwarden has a very good free version. If you don’t want to pay an annual fee to use a password manager, Bitwarden is a great choice.

Read more
I tried both Malwarebytes and Norton, and one came out on top
A PC monitor shows a side-by-side comparison of Malwarebytes and Norton pricing.

Antivirus software is like a safety belt -- it’s protection that you rarely need, but skipping it can be disastrous. That’s why it can be tricky balancing the cost of more expensive plans with the extra security that comes at a premium.

Thankfully, Malwarebytes and Norton offer low-cost options that work with any budget. Let’s compare the prices, plans, and features to determine which is the best antivirus software for your Windows or Mac computer.
Tiers and pricing
Here's a summary of Malwarebytes and Norton antivirus software prices in May 2024. Digital Trends

Read more
I tested the most popular free antivirus apps for Mac. Here are the very best
A MacBook Air is shown with the Bitdefender for Mac dashboard open.

If you’re a Mac user, you probably love the sleek desktop experience and how easy it is to use and understand. Luckily, it's not the most popular target for hackers, but antivirus software is still an important step in securing your Mac and protecting your personal and financial data from malware.

Finding the best antivirus software can be challenging. While subscription prices are affordable, your budget might already be tight. Thankfully, there are several good, free malware solutions for macOS. Here are our top picks for free antivirus software for Mac, each specially tailored to protect your Apple computer.
Bitdefender Virus Scanner

Read more