Symantec fixes Norton vulnerability
Symantec has released an update for Norton SystemWorks after admitting to using a rootkit-type feature in the software package that could provide cyber-criminals a perfect hiding place for malicious code.
The anti-virus vendor has acknowledged it was deliberately hiding a directory from Windows APIs to stop users from deleting files accidentally, but security experts warned this could provide a location for an attacker to hide a malicious file on a computer.
Although Symantec says it is not aware of any attempts by hackers to conceal malicious code in the hidden folder, the company had decided to release an update to eliminate the possibility. The Norton update, which is available through the Symantec LiveUpdate service, will display the previously hidden directory in the Windows interface, allowing it to be scanned by anti-virus products.
Symantec is the second commercial company to receive warnings over the use of rootkit-type techniques to hide files on computers.
Sony BMG faced criticism after anti-rootkit scanners identified the use of stealthy rootkit-type techniques to hide its anti-piracy software. Sony was forced to stop using the technique and recall thousands of CDs after hackers used the software as a hiding place for Trojans.
INet-Bridge