3 ms·
How many other AV programs are extracting/manipulating files without a sandbox? I bet most of them, can probably directly port this method and get same results
by pakled_engineer 11y ago
How many other AV programs are extracting/manipulating files without a sandbox? I bet most of them, can probably directly port this method and get same results
- ploxiln 11y agoThe blog post links to previous analysis of vulnerabilities in Sophos and ESET products. "Many of the vulnerabilities described in this paper could have been severely limited by correct security design, employing modern isolation and exploit mitigation techniques. However, Sophos either disables or opts-out of most major mitigation technologies, even disabling them for other software on the host system." "Unfortunately, analysis of ESET emulation reveals that is not the case and it can be trivially compromised. This report discusses the development of a remote root exploit for an ESET vulnerability and demonstrates how attackers could compromise ESET users." So, yes, definitely.