A security researcher has discovered embarrassing and critical vulnerabilities in Sophos’ enterprise protection software.
Tavis Ormandy, an information security engineer at Google, published a paper along with example attack code to highlight flaws present in Windows, Linux and Mac OS X builds of Sophos’ antivirus product.
The holes can be reliably and easily exploited by hackers to compromise the computers the software is supposed to defend. Specifically, the antivirus scanner fails to safely examine encrypted PDFs and VisualBasic files, which could arrive in an email or website download; these documents can be crafted to trigger flaws within the software and gain control of the system.
Read more: Google bod exposes Sophos Antivirus' gaping holes • The Register